MS.WINS.Replication.Inform2.Integer

NameMS.WINS.Replication.Inform2.Integer.Overflow
Last Updated DateAug 25, 2009
Release DateAug 11, 2009
SeverityCritical
ImpactSystem Compromise: Remote attackers can gain control of vulnerable systems.
DescriptionThis indicates an attack attempt against an integer overflow vulnerability in the Windows Internet Name Service (WINS) on Windows.

The vulnerability exists because the affected software doesn't check user-supplied data which is used to allocate buffer. It may allow a remote attacker to execute arbitrary code via sending a malformed packet.
Affected ProductsWindows 2000 Server
Recommended ActionsApply patch, available from the website.
http://www.microsoft.com/technet/security/Bulletin/MS09-039.mspx
Common Vulnerabilities and Exposures (CVE)http://cve.mitre.org/cgi-bin/cvename.cgi?name=2009-1924
Microsoft Bulletin IDMS09-039   http://www.microsoft.com/technet/security/Bulletin/MS09-039.mspx
Reference: VID-17663