PT-2009-2903 · Microsoft · Windows Print Spooler Service+2
Jun Mao
·
Published
2009-06-10
·
Updated
2018-10-12
·
CVE-2009-0228
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows 2000 SP4
Description
A remote code execution issue exists in the Windows Print Spooler Service, allowing a remote, unauthenticated attacker to execute arbitrary code on an affected system. This could enable the attacker to take complete control of the system, install programs, view, change, or delete data, or create new accounts. The issue is related to a stack-based buffer overflow in the EnumeratePrintShares function in win32spl.dll, which can be triggered by a crafted ShareName in a response to an RPC request.
Recommendations
For Microsoft Windows 2000 SP4, apply the necessary patch to fix the buffer overflow in the Print Spooler Service to prevent remote code execution.
As a temporary workaround, consider restricting access to the Windows Print Spooler Service until a patch is available.
Fix
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows
Windows 2000
Windows Print Spooler Service