|
|
|
Vulnerability Note VU#326746Microsoft Windows RPC service vulnerable to denial of serviceOverviewA vulnerability exists in Microsoft's Remote Procedure Call (RPC) implementation. A remote attacker could exploit this vulnerability to cause a denial of service. An exploit for this vulnerability is publicly available.I. DescriptionMicrosoft has released MS03-039 to address a vulnerability in Microsoft's Remote Procedure Call (RPC) implementation. A denial-of-service vulnerability exists in this service that can be remotely exploited. This vulnerability is not the same as the vulnerability described in CA-2003-16 (MS03-026), however, the impact is similar. An exploit for this vulnerability is publicly available. We have confirmed with Microsoft that this vulnerability only affects Windows 2000 systems.II. ImpactA remote attacker could exploit this vulnerability to cause a denial of service. Although it has been reported that this vulnerability may be used to gain elevated privileges, according to Microsoft's testing, exploitation of this vulnerability can only cause a denial-of-service condition.III. SolutionMicrosoft has released a patch for this vulnerability in MS03-039.Restrict Access
References
This document was written by Damon Morda.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||
|
||||||||||||||||||||||||||||||||||||