PT-2005-1167 · Microsoft · Windows Nt 4.0+3

Derek Soeder

+1

·

Published

2005-02-08

·

Updated

2019-04-30

·

CVE-2005-0045

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Windows NT 4.0 Windows 2000 Windows XP Windows Server 2003
Description The issue arises from the improper validation of certain SMB packets in the Server Message Block implementation. This allows remote attackers to execute arbitrary code via Transaction responses containing Trans or Trans2 commands. Specifically, it can be exploited using Trans2 FIND FIRST2 responses with large file name length fields.
Recommendations For Windows NT 4.0, consider disabling SMB services until a fix is available. For Windows 2000, restrict access to the Trans and Trans2 commands to minimize the risk of exploitation. For Windows XP, avoid using the Trans2 FIND FIRST2 response with large file name length fields in SMB packets until the issue is resolved. For Windows Server 2003, as a temporary workaround, consider limiting the file name length fields in Trans2 responses to prevent arbitrary code execution.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2005-0045

Affected Products

Windows 2000
Windows Nt 4.0
Windows Server 2003
Windows Xp