Vulnerability Note VU#216324

Microsoft ASN.1 Library improperly decodes malformed ASN.1 length values

Original Release date: 10 Feb 2004 | Last revised: 11 Feb 2004

Overview

The Microsoft ASN.1 Library improperly decodes malformed ASN.1 length values which could allow an unauthenticated, remote attacker to execute arbitrary code with SYSTEM privileges.

Description

Abstract Syntax Notation number One (ASN.1) is an international standard used to describe and transmit data packets between applications and across networks. There is a buffer overflow vulnerability in the Microsoft ASN.1 Library that could allow an unauthenticated, remote attacker to execute arbitrary code with SYSTEM privileges on the affected system.

Impact

An unauthenticated, remote attacker could execute arbitrary code with SYSTEM privileges.

Solution

Apply Patch

Apply the patch (828028) referenced in Microsoft Security Bulletin MS04-007.

Systems Affected (Learn More)

VendorStatusDate NotifiedDate Updated
Microsoft CorporationAffected-10 Feb 2004
If you are a vendor and your product is affected, let us know.

CVSS Metrics (Learn More)

Group Score Vector
Base N/A N/A
Temporal N/A N/A
Environmental N/A N/A

References

Credit

This vulnerability was reported by eEye Digital Security.

This document was written by Damon Morda.

Other Information

  • CVE IDs: CAN-2003-0818
  • Date Public: 10 Feb 2004
  • Date First Published: 10 Feb 2004
  • Date Last Updated: 11 Feb 2004
  • Severity Metric: 27.72
  • Document Revision: 18

Feedback

If you have feedback, comments, or additional information about this vulnerability, please send us email.