PT-2004-1674 · Microsoft · Windows Server 2003 64-Bit Edition+4
Yuji Ukai
·
Published
2004-10-16
·
Updated
2018-10-12
·
CVE-2004-0575
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows XP
Microsoft Windows XP 64-bit Edition
Microsoft Windows Server 2003
Microsoft Windows Server 2003 64-bit Edition
Description
The issue is related to an integer overflow in DUNZIP32.DLL, which allows remote attackers to execute arbitrary code. This is made possible by compressed (zipped) folders that involve an "unchecked buffer" and improper length validation.
Recommendations
For Microsoft Windows XP, consider applying security updates or patches to resolve the issue.
For Microsoft Windows XP 64-bit Edition, apply the relevant security fixes to prevent exploitation.
For Microsoft Windows Server 2003, ensure that all security patches are applied to mitigate the risk.
For Microsoft Windows Server 2003 64-bit Edition, update with the latest security updates to fix the issue.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dunzip32.Dll
Windows Server 2003
Windows Server 2003 64-Bit Edition
Windows Xp
Windows Xp 64-Bit Edition