|
|
|
Vulnerability Note VU#778036Microsoft Workstation Service fails to properly parse malformed network messagesOverviewA vulnerability in the way Microsoft Workstation Service parses malformed network messages may lead to execution of arbitrary code.I. DescriptionMicrosoft Workstation Service contains a vulnerability that could be exploited when Workstation Service attempts to parse specially crafted network messages. According to Microsoft Security Bulletin MS06-070:On Windows 2000 Service Pack 4 any anonymous user who could deliver a specially crafted message to the affected system could try to exploit this vulnerability. On Windows XP Service Pack 2 the attack could only be successfully performed by a user with Administrator privileges. II. ImpactA remote, unauthenticated attacker may be able to execute arbitrary code or cause a denial-of-service condition.III. SolutionUpdateMicrosoft has released an update to address this issue. See Microsoft Security Bulletin MS06-070 for more details.
References
This vulnerability was reported in Microsoft Security Bulletin MS06-070. Microsoft credits eEye for reporting this issue. This document was written by Chris Taschner.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
||||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||