PT-2006-3335 · Microsoft · Windows+4

Peter Winter-Smith

·

Published

2006-06-13

·

Updated

2019-04-30

·

CVE-2006-2371

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Windows versions prior to Windows 2000 SP4, XP SP3, and Server 2003 SP2
Description A buffer overflow issue exists in the Remote Access Connection Manager service (RASMAN) of Microsoft Windows, allowing remote attackers to execute arbitrary code via crafted RPC related requests. This leads to registry corruption and stack corruption.
Recommendations For Windows 2000 SP4 and earlier, XP SP1 and SP2, and Server 2003 SP1 and earlier, apply the necessary patches to update to a non-vulnerable version, such as Windows 2000 SP4, XP SP3, or Server 2003 SP2. As a temporary workaround, consider restricting access to the RASMAN service until a patch is available.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-2371

Affected Products

Rasman
Windows
Windows 2000
Windows Server 2003
Windows Xp