PT-2009-4912 · Microsoft · Windows Vista Sp2+2

Published

2009-12-09

·

Updated

2023-12-07

·

CVE-2009-2505

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows Vista SP2 Microsoft Windows Server 2008 SP2
Description A remote code execution issue exists due to improper validation of MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication requests. This allows remote attackers to execute arbitrary code via crafted structures in a malformed request. The issue is caused by incorrect copying into memory of messages received by the server when handling PEAP authentication attempts, which could allow an attacker to take complete control of an affected system.
Recommendations For Microsoft Windows Vista SP2, update the system to address the issue. For Microsoft Windows Server 2008 SP2, update the server to resolve the vulnerability. As a temporary workaround, consider restricting access to the PEAP authentication protocol until a patch is available.

Fix

RCE

Improper Authentication

Weakness Enumeration

Related Identifiers

CVE-2009-2505

Affected Products

Windows Server 2008 R2
Windows Vista Sp2
Windows