vendor:
Windows RSH daemon
by:
MC
N/A
CVSS
N/A
Buffer Overflow
119
CWE
Product Name: Windows RSH daemon
Affected Version From: Windows 2003 SP1 English
Affected Version To: Windows 2000 Pro SP4 English
Patch Exists: NO
Related CWE: CVE-2007-4006
CPE: o:microsoft:windows_2000::sp4
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2007
Windows RSH daemon Buffer Overflow
This module exploits a vulnerabliltiy in Windows RSH daemon 1.8. The vulnerability is due to a failure to check for the length of input sent to the RSH server. A CPORT of 512 -> 1023 must be configured for the exploit to be successful.
Mitigation:
Configure CPORT of 512 -> 1023