SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#647436

Microsoft Windows contains a buffer overflow in the POSIX subsystem

Overview

A buffer overflow vulnerability exists in the Portable Operating System Interface for UNIX (POSIX) subsystem for Windows NT 4.0 and Windows 2000. This vulnerability may be exploited by a local authenticated user to gain full system privileges.

I. Description

Windows NT 4.0 and Windows 2000 provide support to run applications that are created for the Portable Operating System Interface for UNIX (POSIX) standard. For more information about POSIX support, visit the following MSDN Library Website. A buffer overflow vulnerability exists in the POSIX subsystem. A local user may be able to exploit this vulnerability to gain full privileges on the system.

For full details, please see Microsoft Security Bulletin MS04-020.

II. Impact

A local user may be able to exploit this vulnerability to gain full privileges on the system.

III. Solution

Microsoft has provided a patch in Microsoft Security Bulletin MS04-020.

Systems Affected

VendorStatusDate NotifiedDate Updated
Microsoft CorporationVulnerable14-Jul-2004

References


http://www.microsoft.com/technet/security/bulletin/ms04-020.mspx

Credit

Thanks to Microsoft for reporting this vulnerability.

This document was written by Jason A Rafail and is based on Microsoft Security Bulletin MS04-020.

Other Information

Date Public:2004-07-13
Date First Published:2004-07-14
Date Last Updated:2004-07-14
CERT Advisory: 
CVE-ID(s):CAN-2004-0210
NVD-ID(s):CAN-2004-0210
US-CERT Technical Alerts: 
Metric:14.06
Document Revision:5

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2004 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader