PT-2008-4873 · Microsoft · Windows 2000 Sp4+1
Aaron Portnoy
+1
·
Published
2008-10-15
·
Updated
2018-10-12
·
CVE-2008-3479
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows 2000 SP4
Description
The issue is related to a heap-based buffer overflow in the Microsoft Message Queuing (MSMQ) service, allowing remote attackers to read memory contents and execute arbitrary code via a crafted RPC call. This is due to improper processing of parameters to string APIs.
Recommendations
For Microsoft Windows 2000 SP4, consider restricting access to the MSMQ service until a fix is available. As a temporary workaround, disabling the MSMQ service (mqsvc.exe) can help minimize the risk of exploitation.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Msmq
Windows 2000 Sp4