PT-2009-4927 · Microsoft · Windows 2000 Sp4+1

Cody Pierce

·

Publicado

2009-11-11

·

Atualizado

2024-02-09

·

CVE-2009-2523

CVSS v2.0

10

Alta

VetorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows 2000 SP4
Description The issue allows remote attackers to execute arbitrary code via a specially crafted RPC message, which triggers a heap-based buffer overflow. This can be exploited by sending a specially crafted network message to a computer running the License Logging service, allowing an attacker to take complete control of the system. The exploitation does not require authentication.
Recommendations For Microsoft Windows 2000 SP4, consider disabling the License Logging Server service until a patch is available to prevent exploitation. Restrict access to the LlsrLicenseRequestW method to minimize the risk of exploitation. Avoid using the License Logging service in untrusted networks until the issue is resolved.

Correção

RCE

Out of bounds Read

Memory Corruption

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2009-2523

Produtos afetados

Windows 2000 Sp4
Windows