PT-2006-4788 · Microsoft · Windows Server 2003+4

Gerardo Richarte

·

Published

2006-07-31

·

Updated

2018-10-17

·

CVE-2006-3942

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows NT 4.0 Microsoft Windows 2000 Microsoft Windows XP Microsoft Windows Server 2003
Description A denial of service issue exists due to the way the Server service handles certain network messages. This can be exploited by sending a specially crafted network message, potentially causing the system to crash. The issue is related to the ExecuteTransaction function and the handling of SMB messages without null character termination, which can lead to a NULL dereference.
Recommendations For Microsoft Windows NT 4.0, consider disabling the Server service until a patch is available. For Microsoft Windows 2000, restrict access to the Server service to minimize the risk of exploitation. For Microsoft Windows XP, avoid using the Server service for critical operations until the issue is resolved. For Microsoft Windows Server 2003, consider implementing network message filtering to block specially crafted messages.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2006-3942

Affected Products

Windows 2000
Windows Nt 4.0
Windows Server 2003
Windows Xp
Windows