PT-2006-6293 · Microsoft · Remote Installation Service+2

Nicolas Ruff

·

Publicado

2006-12-13

·

Atualizado

2018-10-17

·

CVE-2006-5584

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Microsoft Windows 2000 SP4
Description: The issue concerns the Remote Installation Service (RIS) in Microsoft Windows, which uses a TFTP server allowing anonymous access. This allows remote attackers to upload and overwrite arbitrary files, potentially gaining privileges on systems that use RIS.
Recommendations: For Microsoft Windows 2000 SP4, consider disabling the RIS service or restricting access to the TFTP server to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-5584

Produtos afetados

Windows 2000 Sp4
Remote Installation Service
Tftp Server