|
|
|
|
|
|
|
| |
MS04-007: ASN.1 parsing vulnerability (828028) |
|
| This script is Copyright (C) 2004-2010 Tenable Network Security, Inc. |
|
|
| Family | Windows : Microsoft Bulletins |
| Nessus Plugin ID | 12052 (smb_nt_ms04-007.nasl) |
| Bugtraq ID | 9633 9635 13300
|
| CVE ID | CVE-2003-0818
|
|
| Description: |
Synopsis :
Arbitrary code can be executed on the remote host.
Description :
The remote Windows host has a ASN.1 library which is vulnerable to a
flaw which could allow an attacker to execute arbitrary code on this host.
To exploit this flaw, an attacker would need to send a specially crafted
ASN.1 encoded packet (either an IPsec session negotiation, or an HTTPS request)
with improperly advertised lengths.
A public code is available to exploit this flaw.
Solution :
Microsoft has released a set of patches for Windows NT, 2000, XP and 2003 :
http://www.microsoft.com/technet/security/bulletin/ms04-007.mspx
Risk factor :
Critical / CVSS Base Score : 10.0
(CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C)
|
|
|
|
|
|