PT-2009-2903 · Microsoft · Windows Print Spooler Service+2
Jun Mao
·
Publicado
2009-06-10
·
Atualizado
2018-10-12
·
CVE-2009-0228
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows 2000 SP4
Description
A remote code execution issue exists in the Windows Print Spooler Service, allowing a remote, unauthenticated attacker to execute arbitrary code on an affected system. This could enable the attacker to take complete control of the system, install programs, view, change, or delete data, or create new accounts. The issue is related to a stack-based buffer overflow in the EnumeratePrintShares function in win32spl.dll, which can be triggered by a crafted ShareName in a response to an RPC request.
Recommendations
For Microsoft Windows 2000 SP4, apply the necessary patch to fix the buffer overflow in the Print Spooler Service to prevent remote code execution.
As a temporary workaround, consider restricting access to the Windows Print Spooler Service until a patch is available.
Correção
RCE
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Windows
Windows 2000
Windows Print Spooler Service