vendor:
LSASS Service
by:
hdm
N/A
CVSS
N/A
Stack Buffer Overflow
119
CWE
Product Name: LSASS Service
Affected Version From: Windows 2000 English
Affected Version To: Windows XP English
Patch Exists: NO
Related CWE: CVE-2003-0533, OSVDB-5248, BID-10108, MSB-MS04-011
CPE: N/A
Metasploit:
N/A
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=12205, https://www.infosecmatter.com/nessus-plugin-library/?id=12209, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/windows/smb/ms04_011_lsass, https://www.infosecmatter.com/nessus-plugin-library/?id=45372, https://www.infosecmatter.com/nessus-plugin-library/?id=45373, https://www.infosecmatter.com/nessus-plugin-library/?id=72834, https://www.infosecmatter.com/list-of-metasploit-windows-exploits-detailed-spreadsheet/, https://www.infosecmatter.com/nessus-plugin-library/?id=33441, https://www.infosecmatter.com/nessus-plugin-library/?id=33905, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/windows/smb/ms04_011_lsass, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/windows/imap/mdaemon_fetch, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/windows/smb/ms04_011_lsass, https://www.infosecmatter.com/nessus-plugin-library/?id=84203, https://www.infosecmatter.com/nessus-plugin-library/?id=84426
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2004
Microsoft LSASS Service DsRolerUpgradeDownlevelServer Overflow
This module exploits a stack buffer overflow in the LSASS service, this vulnerability was originally found by eEye. When re-exploiting a Windows XP system, you will need need to run this module twice. DCERPC request fragmentation can be performed by setting 'FragSize' parameter.
Mitigation:
No known mitigation or remediation for this vulnerability