PT-2005-1167 · Microsoft · Windows Nt 4.0+3
Derek Soeder
+1
·
Published
2005-02-08
·
Updated
2019-04-30
·
CVE-2005-0045
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Windows NT 4.0
Windows 2000
Windows XP
Windows Server 2003
Description
The issue arises from the improper validation of certain SMB packets in the Server Message Block implementation. This allows remote attackers to execute arbitrary code via Transaction responses containing Trans or Trans2 commands. Specifically, it can be exploited using Trans2 FIND FIRST2 responses with large file name length fields.
Recommendations
For Windows NT 4.0, consider disabling SMB services until a fix is available.
For Windows 2000, restrict access to the Trans and Trans2 commands to minimize the risk of exploitation.
For Windows XP, avoid using the Trans2 FIND FIRST2 response with large file name length fields in SMB packets until the issue is resolved.
For Windows Server 2003, as a temporary workaround, consider limiting the file name length fields in Trans2 responses to prevent arbitrary code execution.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows 2000
Windows Nt 4.0
Windows Server 2003
Windows Xp