This
security update resolves a privately reported vulnerability in Virtual
Address Descriptor. The vulnerability could allow elevation of
privilege if a user runs a specially crafted application. An
authenticated attacker who successfully exploited this vulnerability
could gain elevation of privilege on an affected system. An attacker
could then install programs; view, change, or delete data; or create
new accounts with full administrative rights.
This security
update is rated Important for all supported editions of Windows XP,
Windows Server 2003, Windows Vista, and Windows Server 2008. For more
information, see the subsection, Affected and Non-Affected Software, in this section.
The
security update addresses the vulnerability by modifying the way that
Virtual Address Descriptor handles memory allocation variables. For
more information about the vulnerability, see the Frequently Asked
Questions (FAQ) subsection for the specific vulnerability entry under
the next section, Vulnerability Information.
Recommendation. Microsoft recommends that customers apply the update at the earliest opportunity.
Known Issues. None
The
following software have been tested to determine which versions or
editions are affected. Other versions or editions are either past their
support life cycle or are not affected. To determine the support life
cycle for your software version or edition, visit Microsoft Support Lifecycle.