PT-2009-4927 · Microsoft · Windows 2000 Sp4+1
Cody Pierce
·
Publicado
2009-11-11
·
Atualizado
2024-02-09
·
CVE-2009-2523
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows 2000 SP4
Description
The issue allows remote attackers to execute arbitrary code via a specially crafted RPC message, which triggers a heap-based buffer overflow. This can be exploited by sending a specially crafted network message to a computer running the License Logging service, allowing an attacker to take complete control of the system. The exploitation does not require authentication.
Recommendations
For Microsoft Windows 2000 SP4, consider disabling the License Logging Server service until a patch is available to prevent exploitation. Restrict access to the LlsrLicenseRequestW method to minimize the risk of exploitation. Avoid using the License Logging service in untrusted networks until the issue is resolved.
Correção
RCE
Out of bounds Read
Memory Corruption
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Windows 2000 Sp4
Windows