vendor:
Windows Server 2003
by:
Víctor Portal
7.5
CVSS
HIGH
Arbitrary Pointer Dereference
CWE
Product Name: Windows Server 2003
Affected Version From: Windows Server 2003
Affected Version To: Windows Server 2003
Patch Exists: NO
Related CWE:
CPE: o:microsoft:windows_server_2003
Platforms Tested: Windows Server 2003
Arbitrary Pointer Dereference in Windows Server 2003
The exploited vulnerability is an arbitrary pointer dereference affecting the dwVarID field of the MIB_OPAQUE_QUERY structure. The dwVarID is used as a pointer to an array of functions and the application does not check if the pointer is pointing out of the bounds of the array, allowing for remote code execution. This exploit is tested in Windows Server 2003 SP2 (ES) with RRAS service enabled.
Mitigation:
Consider disabling the RRAS service if you are still using Windows Server 2003.