Jump to content

Does KB2686509 need to be run on a fresh system? Keyboard layout vulne


Guest

Recommended Posts

  • 1 month later...

I'm finding this patch is a complete mess, and in researching the problems I'm having with installing it, I found 2 or 3 different scenarios where it fails to install. I'm not seeing where Microsoft made a solid fix for this either.

Link to comment
Share on other sites

This prompts IMHO a "side" question.

I don't get it.

http://support.microsoft.com/kb/2686509/en-us

This security update enables fixes to a problem that can occur with the loading of keyboard layout files. You must install this update and security update 2676562 to protect the system against vulnerabilities that could arise from loading keyboard layout files from untrusted locations.

Has anyone ever loaded a keyboard layout files from untrusted location? :w00t:

Seriously, I cannot even think about what a possible scenario for this is.

The article refers to:

http://technet.microsoft.com/en-us/security/bulletin/ms12-034

which (about the keyboard layout issue) refers to:

http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0181

Description
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7 Gold and SP1, and Windows 8 Consumer Preview does not properly manage Keyboard Layout files, which allows local users to gain privileges via a crafted application, aka "Keyboard Layout File Vulnerability."

So, it seems that the issue is actually a LOCAL user that could gain privileges.

Not something I would lose my sleep about. :unsure:

jaclaz

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...