PT-2006-4788 · Microsoft · Windows Server 2003+4
Gerardo Richarte
·
Published
2006-07-31
·
Updated
2018-10-17
·
CVE-2006-3942
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows NT 4.0
Microsoft Windows 2000
Microsoft Windows XP
Microsoft Windows Server 2003
Description
A denial of service issue exists due to the way the Server service handles certain network messages. This can be exploited by sending a specially crafted network message, potentially causing the system to crash. The issue is related to the
ExecuteTransaction function and the handling of SMB messages without null character termination, which can lead to a NULL dereference.Recommendations
For Microsoft Windows NT 4.0, consider disabling the Server service until a patch is available.
For Microsoft Windows 2000, restrict access to the Server service to minimize the risk of exploitation.
For Microsoft Windows XP, avoid using the Server service for critical operations until the issue is resolved.
For Microsoft Windows Server 2003, consider implementing network message filtering to block specially crafted messages.
Exploit
Fix
DoS
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows 2000
Windows Nt 4.0
Windows Server 2003
Windows Xp
Windows