PT-2006-6293 · Microsoft · Remote Installation Service+2
Nicolas Ruff
·
Published
2006-12-13
·
Updated
2018-10-17
·
CVE-2006-5584
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Microsoft Windows 2000 SP4
Description:
The issue concerns the Remote Installation Service (RIS) in Microsoft Windows, which uses a TFTP server allowing anonymous access. This allows remote attackers to upload and overwrite arbitrary files, potentially gaining privileges on systems that use RIS.
Recommendations:
For Microsoft Windows 2000 SP4, consider disabling the RIS service or restricting access to the TFTP server to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows 2000 Sp4
Remote Installation Service
Tftp Server