PT-2008-4873 · Microsoft · Windows 2000 Sp4+1

Aaron Portnoy

+1

·

Published

2008-10-15

·

Updated

2018-10-12

·

CVE-2008-3479

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows 2000 SP4
Description The issue is related to a heap-based buffer overflow in the Microsoft Message Queuing (MSMQ) service, allowing remote attackers to read memory contents and execute arbitrary code via a crafted RPC call. This is due to improper processing of parameters to string APIs.
Recommendations For Microsoft Windows 2000 SP4, consider restricting access to the MSMQ service until a fix is available. As a temporary workaround, disabling the MSMQ service (mqsvc.exe) can help minimize the risk of exploitation.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-3479

Affected Products

Msmq
Windows 2000 Sp4