|
|
|
Vulnerability Note VU#638548Microsoft Windows SSP interface fails to properly validate value used during authentication protocol selectionOverviewA remotely exploitable vulnerability in Microsoft's Negotiate Security Software Provider (SSP) interface could permit an attacker to execute arbitrary code on the system.I. DescriptionMicrosoft's Negotiate Security Software Provider (SSP) interface contains a buffer overflow during the processing of data sent for authentication protocol selection. A unathenticated remote attacker could send a malicious request to the SSP service to exploit this vulnerability. The following systems are affected:
II. ImpactAn unauthenticated remote attacker could cause a denial-of-service situation, or potentially execute arbitrary code on the system with "SYSTEM" privileges.III. SolutionApply a patch from the vendor
References
Thanks to Microsoft for reporting this vulnerability. This document was written by Jason A Rafail.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||