int(1507)

Vulnerability Bulletins


Desbordamiento de búfer en Message Queuing de Microsoft Windows

Vulnerability classification

Property Value
Confidence level Oficial
Impact Compromiso Root
Dificulty Principiante
Required attacker level Acceso remoto sin cuenta a un servicio exotico

System information

Property Value
Affected manufacturer Microsoft
Affected software Microsoft Windows 2000 Service Pack 3
Microsoft Windows 2000 Service Pack 4
Microsoft Windows XP Service Pack 1
Microsoft Windows XP 64-Bit Edition Service Pack 1 (Itanium)
Microsoft Windows 98
Microsoft Windows 98 Second Edition (SE)

Description

Se ha descubierto una vulnerabilidad de desbordamiento de búfer en el componente (no instalado por defecto) Message Queuing de Microsoft Windows.

La explotación de esta vulnerabilidad podría permitir a un atacante remoto obtener el control total de un sistema afectado.

Solution



Actualización de software

Microsoft
Microsoft Windows 2000 Service Pack 3
Microsoft Windows 2000 Service Pack 4
http://www.microsoft.com/downloads/details.aspx?FamilyId=99A8EE12-4BD6-43F5-A43F-124E0E2C2283
Microsoft Windows XP Service Pack 1
http://www.microsoft.com/downloads/details.aspx?FamilyId=D72B7198-93A8-4652-B505-8E51FC5EEAC3
Microsoft Windows XP 64-Bit Edition Service Pack 1 (Itanium)
http://www.microsoft.com/downloads/details.aspx?FamilyId=9124BA48-73A8-4C94-AA46-CE9A9D1E1198

Standar resources

Property Value
CVE CAN-2005-0059
BID

Other resources

Microsoft Security Bulletin MS05-017
http://www.microsoft.com/technet/security/Bulletin/MS05-017.mspx

Version history

Version Comments Date
1.0 Aviso emitido 2005-04-13
2.0 Exploit público disponible 2005-06-30
Ministerio de Defensa
CNI
CCN
CCN-CERT