>> Microsoft Malware Protection Engine Remote DoS Vulnerability (MS08-029)
Title : Microsoft Malware Protection Engine Remote DoS Vulnerability (MS08-029) VUPEN ID : VUPEN/ADV-2008-1506 CVE ID : CVE-2008-1437 - CVE-2008-1438
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-05-13
Technical Description
Two vulnerabilities have been identified in various Microsoft products, which could be exploited by attackers or malware to cause a denial of service.
The first issue is caused by an error in the Malware Protection Engine that does not properly validate input when parsing specially crafted files, which could be exploited to cause an affected application to become non-responsive and restart.
The second vulnerability is caused by an error in the Microsoft Malware Protection Engine that does not properly validate certain data structures when parsing files, which can be exploited to fill up a system's disk space, leading to a denial of service condition.