This application requires Javascript for optimal performance.

MS.WINS.Replication.Inform2.Integer.Overflow

Release Date

Aug 11, 2009

Severity

critical

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Description

This indicates an attack attempt against an integer overflow vulnerability in the Windows Internet Name Service (WINS) on Windows.

The vulnerability exists because the affected software doesn't check user-supplied data which is used to allocate buffer. It may allow a remote attacker to execute arbitrary code via sending a malformed packet.

Affected Products

Windows 2000 Server

Recommended Actions

Apply patch, available from the website.
http://www.microsoft.com/technet/security/Bulletin/MS09-039.mspx

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2009-1924

Reference/s

http://www.microsoft.com/technet/security/Bulletin/MS09-039.mspx (MS-ID)

Reference: VID-17663