PT-2005-3057 · Microsoft · Msdtc

Fang Xing

·

Publicado

2005-10-11

·

Atualizado

2018-10-12

·

CVE-2005-2119

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions: Microsoft Distributed Transaction Coordinator (MSDTC) (affected versions not specified)
Description: The issue concerns the MIDL user allocate function in the MSDTC proxy, which allocates a fixed size of memory regardless of the actual size required. This allows attackers to potentially overwrite arbitrary memory locations by providing an incorrect size value to the NdrAllocate function, leading to writing management data outside the allocated buffer.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2005-2119

Produtos afetados

Msdtc