PT-2011-2986 · Microsoft · Windows Server 2008 Gold+3

Published

2011-05-10

·

Updated

2020-09-28

·

CVE-2011-1248

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows Server 2003 SP2 Microsoft Windows Server 2008 Gold Microsoft Windows Server 2008 SP2 Microsoft Windows Server 2008 R2 Microsoft Windows Server 2008 R2 SP1
Description The issue is related to the WINS service in Microsoft Windows Server, which does not properly handle socket send exceptions. This allows remote attackers to execute arbitrary code or cause a denial of service due to memory corruption via crafted packets. The problem is related to unintended stack-frame values and buffer passing.
Recommendations For Microsoft Windows Server 2003 SP2, update to a version that includes the fix for this issue. For Microsoft Windows Server 2008 Gold, apply the necessary patch or update to resolve the vulnerability. For Microsoft Windows Server 2008 SP2, install the relevant security update to fix the issue. For Microsoft Windows Server 2008 R2, apply the appropriate patch to mitigate the risk. For Microsoft Windows Server 2008 R2 SP1, update to a newer version that includes the fix for this vulnerability.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2011-1248
ZDI-11-167

Affected Products

Windows Server 2003 Sp2
Windows Server 2008 Gold
Windows Server 2008 R2
Windows Server 2008 R2 Sp1