Vulnerability Note VU#908276
Microsoft Winsock buffer overflow
Overview
A buffer overflow vulnerability in Microsoft Winsock may allow a remote attacker to execute arbitrary code on an affected system.
Description
Winsock (Windows Socket 2) allows network applications to relay data across a network regardless of the network protocol being used. Microsoft's Winsock contains a buffer overflow vulnerability that can allow a remote attacker to execute arbitrary code and gain control of the affected system. Exploitation of this vulnerability occurs when the remote attacker can convince the user to open a specially crafted file or website. Microsoft's bulletin states that the following Windows operating systems are affected by this vulnerability:
|
Impact
A remote attacker who can successfully convince a user to open a specially crafted file or website may be able to execute arbitrary code and gain control of the affected system. |
Solution
Apply an update
|
Workaround
Modifying the Autodial DLL in the Windows registry will prevent specially crafted files and websites from invoking the affected API. Please see the Microsoft Security Bulletin MS06-041 for further details and cautions regarding use of the Registry Editor. * Note that this workaround does NOT fix the underlying vulnerability but will help block known methods of attack. |
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Microsoft Corporation | Affected | - | 08 Aug 2006 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
Credit
Thanks to Microsoft Security for reporting this vulnerability in Microsoft Security Bulletin MS06-041. Microsoft, in turn, thanks Peter Winter Smith of NGS Software for reporting the vulnerability to them.
This document was written by Katie Washok.
Other Information
- CVE IDs: CVE-2006-3440
- Date Public: 08 Aug 2006
- Date First Published: 08 Aug 2006
- Date Last Updated: 08 Aug 2006
- Severity Metric: 12.83
- Document Revision: 24
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.