PT-2004-1667 · Microsoft · Windows Nt Server+4
Kostya Kortchinsky
·
Published
2004-12-31
·
Updated
2019-04-30
·
CVE-2004-0567
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Windows NT Server version 4.0 SP 6a
Windows NT Terminal Server version 4.0 SP 6
Windows 2000 Server versions SP3 and SP4
Windows Server 2003 (affected versions not specified)
Description
The issue arises from improper validation of the computer name value in a WINS packet by the Windows Internet Naming Service (WINS), allowing remote attackers to execute arbitrary code or cause a denial of service, resulting in a server crash. This is due to an "unchecked buffer" that may trigger a buffer overflow.
Recommendations
For Windows NT Server version 4.0 SP 6a, update to a version that includes the fix for the Name Validation issue.
For Windows NT Terminal Server version 4.0 SP 6, update to a version that includes the fix for the Name Validation issue.
For Windows 2000 Server versions SP3 and SP4, update to a version that includes the fix for the Name Validation issue.
For Windows Server 2003, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows 2000 Server
Windows Internet Naming Service
Windows Nt Server
Windows Nt Terminal Server
Windows Server 2003