PT-2011-2986 · Microsoft · Windows Server 2008 Gold+3
Published
2011-05-10
·
Updated
2020-09-28
·
CVE-2011-1248
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Server 2003 SP2
Microsoft Windows Server 2008 Gold
Microsoft Windows Server 2008 SP2
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2008 R2 SP1
Description
The issue is related to the WINS service in Microsoft Windows Server, which does not properly handle socket send exceptions. This allows remote attackers to execute arbitrary code or cause a denial of service due to memory corruption via crafted packets. The problem is related to unintended stack-frame values and buffer passing.
Recommendations
For Microsoft Windows Server 2003 SP2, update to a version that includes the fix for this issue.
For Microsoft Windows Server 2008 Gold, apply the necessary patch or update to resolve the vulnerability.
For Microsoft Windows Server 2008 SP2, install the relevant security update to fix the issue.
For Microsoft Windows Server 2008 R2, apply the appropriate patch to mitigate the risk.
For Microsoft Windows Server 2008 R2 SP1, update to a newer version that includes the fix for this vulnerability.
Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows Server 2003 Sp2
Windows Server 2008 Gold
Windows Server 2008 R2
Windows Server 2008 R2 Sp1