Check Point Reference: | CPAI-2006-139 |
Date Published: | 30 Nov 2006 |
Severity: | High |
Last Updated: | Thursday 26 April, 2007 |
Source: | Microsoft Security Bulletin MS06-070 |
Industry Reference: | CVE-2006-4691 |
Protection Provided by: | |
Who is Vulnerable? | Microsoft Windows 2000 SP4 Microsoft Windows XP SP2 |
Vulnerability Description | A denial of service vulnerability was detected in Microsoft Windows Workstation service. The workstation service manages the routing of system requests. The workstation service library file (wkssvc.dll) is used by windows when working with shared network drives and printers. A remote attacker could exploit this vulnerability to cause denial of service or to execute arbitrary code on a target system. |
Update/Patch Avaliable | Apply patches: Microsoft Security Bulletin MS06-070 |
Vulnerability Details | This vulnerability is due to a buffer overflow error in the workstation service when processing malformed RPC requests. An attacker can exploit this flaw by sending a malformed RPC request with an overly long hostname. Successful exploitation of the vulnerability could allow remote attackers to cause denial of service and to execute arbitrary code on an affected system. |