PT-2011-2986 · Microsoft · Windows Server 2008 Gold+3

Publicado

2011-05-10

·

Atualizado

2020-09-28

·

CVE-2011-1248

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows Server 2003 SP2 Microsoft Windows Server 2008 Gold Microsoft Windows Server 2008 SP2 Microsoft Windows Server 2008 R2 Microsoft Windows Server 2008 R2 SP1
Description The issue is related to the WINS service in Microsoft Windows Server, which does not properly handle socket send exceptions. This allows remote attackers to execute arbitrary code or cause a denial of service due to memory corruption via crafted packets. The problem is related to unintended stack-frame values and buffer passing.
Recommendations For Microsoft Windows Server 2003 SP2, update to a version that includes the fix for this issue. For Microsoft Windows Server 2008 Gold, apply the necessary patch or update to resolve the vulnerability. For Microsoft Windows Server 2008 SP2, install the relevant security update to fix the issue. For Microsoft Windows Server 2008 R2, apply the appropriate patch to mitigate the risk. For Microsoft Windows Server 2008 R2 SP1, update to a newer version that includes the fix for this vulnerability.

Exploit

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2011-1248
ZDI-11-167

Produtos afetados

Windows Server 2003 Sp2
Windows Server 2008 Gold
Windows Server 2008 R2
Windows Server 2008 R2 Sp1