Your Ad Here
首页 | 编程语言 | 网站建设 | 游戏天堂 | 冲浪宝典 | 网络安全 | 操作系统 | 软件时空 | 硬件指南 | 病毒相关 | IT 认证
软讯网络 > 编程语言 > .NET > C#.NET > Microsoft Windows DNS Service RPC Stack Overflow Lets Remote Users Execute Arbitrary Code
【标  题】:Microsoft Windows DNS Service RPC Stack Overflow Lets Remote Users Execute Arbitrary Code
【关键字】:Microsoft,Windows,DNS,Service,RPC,Stack,Overflow,Lets,Remote,Users,Execute,Arbitrary,Code
【来  源】:http://blog.csdn.net/iiprogram/archive/2007/04/16/1566113.aspx

Microsoft Windows DNS Service RPC Stack Overflow Lets Remote Users Execute Arbitrary Code

Your Ad Here
Version(s): Windows 2000 Server SP4, Windows Server 2003 SP1, and Windows 2003 SP2
Description:  A vulnerability was reported in the Windows DNS service RPC interface. A remote user can execute arbitrary code on the target system.

A remote user can send a specially crafted RPC packet to the RPC interface of the DNS server to trigger a stack overflow and execute arbitrary code on the target system. The code will run with the privileges of the target DNS service, which runs with Local System privileges by default.

A remote authenticated user can also exploit this vulnerability via TCP/UDP port 445.

The name resolution function running on port 53 is not affected.

The vulnerable code resides on Windows server systems, not client systems.

Windows 2000 Professional SP4, Windows XP SP2, and Windows Vista are not affected.

This vulnerability is being actively exploited in limited situations.

Carnegie Mellon reported this vulnerability to Microsoft.

Impact:  A remote user can execute arbitrary code on the target system.
Solution:  No solution was available at the time of this entry.

Microsoft is working on a fix.

The Microsoft advisory is available at:

http://www.microsoft.com/technet/security/advisory/935964.mspx

Vendor URL:  www.microsoft.com/technet/security/advisory/935964.mspx (Links to External Site)
Cause:  Boundary error
Underlying OS:  Windows (2000), Windows (2003)
 
Microsoft Windows DNS RPC Buffer Overflow:【上一篇】
Windows DNS DnssrvQuery() Stack Overflow:【下一篇】
【相关文章】
  • Microsoft Windows DNS RPC Buffer Overflow
  • 微软WebService之MapPoint分析手记(二):MapPoint接口架构一览
  • Windows中的待机和休眠
  • Windows与Linux系统谁更安全 红旗呼吁停止口水战
  • 用Delphi开发支持Unicode可参考的资源
  • .net 2005 环境下,写Microsoft Outlook的Add-in的注意事项
  • 《给初学者的Windows Vista的补遗手册》之073
  • 《给初学者的Windows Vista的补遗手册》之074
  • RAS3U3 xwindows rpms
  • Windows动态库与Linux共享对象
  • 【随机文章】
  • photoshop复制小技巧一则
  • ASP.Net调试之三板斧:第二招
  • javascript 框架间函数传递
  • Windows XP SP2 ADSL 拨号无法上网,提示”受限制或无连接“
  • 供应商关系管理(SRM)能给企业带来什么?
  • 谈软件公司的技术管理
  • Solaris自动注销
  • 让你顿悟的115条慧言
  • sed中文手册
  • Linux对绝Windows之十三篇
  • 【相关评论】
    没有相关评论
    【发表评论】
    姓名:
    邮件:
    随机码*
    评论*
          
    |  首 页  |  版权声明  |  联系我们   |  网站地图  |
    CopyRight © 2004-2007 软讯网络 All Rigths Reserved.