PT-2008-4873 · Microsoft · Windows 2000 Sp4+1

Aaron Portnoy

+1

·

Publicado

2008-10-15

·

Atualizado

2018-10-12

·

CVE-2008-3479

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows 2000 SP4
Description The issue is related to a heap-based buffer overflow in the Microsoft Message Queuing (MSMQ) service, allowing remote attackers to read memory contents and execute arbitrary code via a crafted RPC call. This is due to improper processing of parameters to string APIs.
Recommendations For Microsoft Windows 2000 SP4, consider restricting access to the MSMQ service until a fix is available. As a temporary workaround, disabling the MSMQ service (mqsvc.exe) can help minimize the risk of exploitation.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-3479

Produtos afetados

Msmq
Windows 2000 Sp4