PT-2007-4331 · Microsoft · Message Queuing (Msmq) Service+4
Axis
+1
·
Published
2007-12-11
·
Updated
2018-10-16
·
CVE-2007-3039
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Microsoft Windows versions prior to Windows XP SP3
Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4
Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Professional SP4
Microsoft Message Queuing (MSMQ) service in Microsoft Windows XP SP2
Description:
A stack-based buffer overflow issue exists in the Microsoft Message Queuing (MSMQ) service, allowing attackers to execute arbitrary code via a long string in an opnum 0x06 RPC call to port 2103. This issue is remotely exploitable on Windows 2000 Server. The vulnerability occurs when the Message Queuing Service incorrectly validates input strings before passing them to a buffer. An attacker could exploit this by constructing a specially crafted MSMQ message, potentially allowing remote code execution on Microsoft Windows 2000 and local elevation of privilege on Windows XP.
Recommendations:
For Microsoft Windows 2000 Server SP4, consider disabling the MSMQ service until a patch is available.
For Microsoft Windows 2000 Professional SP4, restrict access to the MSMQ service to minimize the risk of exploitation.
For Microsoft Windows XP SP2, avoid using the MSMQ service in a local scenario until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
RCE
DoS
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Message Queuing (Msmq) Service
Windows
Windows 2000 Professional
Windows 2000 Server
Windows Xp