PT-2009-4912 · Microsoft · Windows Vista Sp2+2
Published
2009-12-09
·
Updated
2023-12-07
·
CVE-2009-2505
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Vista SP2
Microsoft Windows Server 2008 SP2
Description
A remote code execution issue exists due to improper validation of MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication requests. This allows remote attackers to execute arbitrary code via crafted structures in a malformed request. The issue is caused by incorrect copying into memory of messages received by the server when handling PEAP authentication attempts, which could allow an attacker to take complete control of an affected system.
Recommendations
For Microsoft Windows Vista SP2, update the system to address the issue.
For Microsoft Windows Server 2008 SP2, update the server to resolve the vulnerability.
As a temporary workaround, consider restricting access to the PEAP authentication protocol until a patch is available.
Fix
RCE
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows Server 2008 R2
Windows Vista Sp2
Windows