Vulnerability Note VU#388900
Microsoft Web Client Service vulnerable to buffer overflow
Overview
A buffer overflow in the message handling routines of the Microsoft Web Client Service may allow a remote, authenticated attacker to execute arbitrary code on a vulnerable system.
Description
According to Microsoft, the Web Client Service: allows applications to access documents on the Internet. Web Client extends the networking capability of Windows by allowing standard Win32 applications to create, read, and write files on Internet file servers by using the WebDAV protocol. The WebDAV protocol is a file-access protocol that is described in XML and that travels over the Hypertext Transfer Protocol (HTTP). By using standard HTTP, WebDAV runs over the existing Internet infrastructure. For example, WebDAV runs over firewalls and routers. The Web Client Service is disabled by default on Windows Server 2003, but may be enabled by default in Microsoft Windows XP. For more information about affected components, please refer to MS06-008. This Bulletin supplants Microsoft Security Bulletin MS05-028. |
Impact
A remote attacker with valid login credentials may be able to exploit this vulnerability to execute arbitrary code. |
Solution
Apply An Update |
Please see Microsoft Security Bulletin MS06-009 for a list of workarounds to mitigate this vulnerability. |
Systems Affected
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Microsoft Corporation | Vulnerable | - | 14 Feb 2006 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.microsoft.com/technet/security/bulletin/ms06-008.mspx
- http://www.microsoft.com/technet/security/Bulletin/MS05-028.mspx
Credit
This vulnerability was reported in Microsoft Security Bulletin MS06-008. Microsoft credits Kostya Kortchinsky of EADS/CRC with providing information regarding this issue.
This document was written by Jeff Gennari.
Other Information
- CVE IDs: CVE-2006-0013
- Date Public: 14 Feb 2006
- Date First Published: 14 Feb 2006
- Date Last Updated: 14 Feb 2006
- Severity Metric: 5.68
- Document Revision: 15
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.
This product is provided subject to the Notification as indicated here: http://www.us-cert.gov/legal.html#notify