vendor:
NetDDE Service
by:
pusscat
N/A
CVSS
N/A
Stack Buffer Overflow
119
CWE
Product Name: NetDDE Service
Affected Version From: Windows 2000 SP4
Affected Version To: Windows XP SP0
Patch Exists: YES
Related CWE: CVE-2004-0206
CPE: 2.6.2:2000::sp4
Metasploit:
N/A
Other Scripts:
https://www.infosecmatter.com/nessus-plugin-library/?id=15456, https://www.infosecmatter.com/nessus-plugin-library/?id=15572, https://www.infosecmatter.com/metasploit-module-library/?mm=exploit/windows/smb/ms04_031_netdde, https://www.infosecmatter.com/list-of-metasploit-windows-exploits-detailed-spreadsheet/
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2004
Microsoft NetDDE Service Overflow
This module exploits a stack buffer overflow in the NetDDE service, which is the precursor to the DCOM interface. This exploit effects only operating systems released prior to Windows XP SP1 (2000 SP4, XP SP0). Despite Microsoft's claim that this vulnerability can be exploited without authentication, the NDDEAPI pipe is only accessible after successful authentication.
Mitigation:
Microsoft has released a patch for this vulnerability