This application requires Javascript for optimal performance.

MS.Windows.WINS.Memory.Corruption

Alias(es)

MS.WINS.Arbitrary.Memory.Write.C

Release Date

Sep 11, 2006

Severity

critical

Impact

An attacker who has successfully exploited this vulnerability could have complete control of the affected system.

Description

This indicates a possible attempt to exploit a vulnerability in Microsoft WINS server.

Microsoft Windows Internet Naming Service (WINS) provides a service that maps NETBIOS names to IP addresses. It has been reported that WINS has a vulnerability in its replication protocol which allows a remote user to specify the location of the association context. By controlling the location and contents of this data structure, a remote attacker can overwrite a small block of memory at an arbitrary location.

Affected Products

Any unprotected WINS server running on Microsoft Windows NT 4.0 Server, Microsoft Windows 2000 Server, and Microsoft Windows 2003 Server is vulnerable.

Recommended Actions

Apply the appropriate patch, as specified in Microsoft Security Bulletin MS04-045:
http://www.microsoft.com/technet/security/bulletin/MS04-045.mspx

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2004-1080

Reference/s

http://www.kb.cert.org/vuls/id/145134
http://technet.microsoft.com/en-us/security/bulletin/MS04-045.mspx (MS-ID)

Reference: VID-12235