vendor:
Windows
by:
SecurityFocus
7.5
CVSS
HIGH
Buffer Overrun
120
CWE
Product Name: Windows
Affected Version From: Windows 2000
Affected Version To: Windows XP
Patch Exists: YES
Related CWE: CVE-2002-0392
CPE: o:microsoft:windows_xp
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows, Windows 9x, Windows 98
2002
Buffer Overrun Vulnerability in Microsoft Windows
A buffer overrun vulnerability has been reported in Microsoft Windows that can be exploited remotely via a DCOM RPC interface that listens on TCP/UDP port 135. The issue is due to insufficient bounds checking of client DCOM object activation requests. Exploitation of this issue could result in execution of malicious instructions with Local System privileges on an affected system. This issue may be exposed on other ports that the RPC Endpoint Mapper listens on, such as TCP ports 139, 135, 445 and 593. This has not been confirmed. Under some configurations the Endpoint Mapper may receive traffic via port 80.
Mitigation:
Apply the patch from Microsoft or disable DCOM on the affected system.