MS.Windows.Troubleshooter.RunQuery2

NameMS.Windows.Troubleshooter.RunQuery2.Code.Execution
Last Updated DateFeb 02, 2010
Release DateAug 10, 2005
SeverityHigh
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt to exploit a memory corruption vulnerability in Microsoft Windows.

The vulnerability is located in the Troubleshoot ActiveX control through miss-use of "RunQuery2" method. It may allow remote attackers to execute arbitrary code in the context of the application using the affected ActiveX control. Failed exploit attempts will likely cause the program to crash,resulting in a denial of service condition.
Affected ProductsWindows 2000 SP4 and earlier versions.
Recommended ActionsApply patch, available from the web site:
http://www.microsoft.com/technet/security/Bulletin/MS03-042.mspx
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2003-0662
Microsoft Bulletin IDMS03-042   http://www.microsoft.com/technet/security/Bulletin/MS03-042.mspx
Reference/shttp://www.securityfocus.com/bid/8833 (BugTraq)
Reference: VID-10653