vendor:
CA BrightStor
by:
Winny M Thomas
7.5
CVSS
HIGH
Stack Overflow
121
CWE
Product Name: CA BrightStor
Affected Version From:
Affected Version To:
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Windows 2000 SP4
Unknown
CA BrightStor msgeng.exe service stack overflow
Remote exploit for the CA BrightStor msgeng.exe service stack overflow vulnerability. The exploit opens a shell on TCP port 4444. The vulnerability is caused by a stack overflow in the strcpy function. The user-supplied data is stored in the heap and the first DWORD of the RPC stub is used as the source address in the strcpy operation.
Mitigation:
Apply the patch provided by the vendor.