PT-2009-2903 · Microsoft · Windows Print Spooler Service+2

Jun Mao

·

Publicado

2009-06-10

·

Atualizado

2018-10-12

·

CVE-2009-0228

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows 2000 SP4
Description A remote code execution issue exists in the Windows Print Spooler Service, allowing a remote, unauthenticated attacker to execute arbitrary code on an affected system. This could enable the attacker to take complete control of the system, install programs, view, change, or delete data, or create new accounts. The issue is related to a stack-based buffer overflow in the EnumeratePrintShares function in win32spl.dll, which can be triggered by a crafted ShareName in a response to an RPC request.
Recommendations For Microsoft Windows 2000 SP4, apply the necessary patch to fix the buffer overflow in the Print Spooler Service to prevent remote code execution. As a temporary workaround, consider restricting access to the Windows Print Spooler Service until a patch is available.

Correção

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-0228

Produtos afetados

Windows
Windows 2000
Windows Print Spooler Service