Overview
A remotely exploitable vulnerability in Microsoft's Negotiate Security Software Provider (SSP) interface could permit an attacker to execute arbitrary code on the system.
Description
Microsoft's Negotiate Security Software Provider (SSP) interface contains a buffer overflow during the processing of data sent for authentication protocol selection. A unathenticated remote attacker could send a malicious request to the SSP service to exploit this vulnerability. The following systems are affected:
|
Impact
An unauthenticated remote attacker could cause a denial-of-service situation, or potentially execute arbitrary code on the system with "SYSTEM" privileges. |
Solution
Apply a patch from the vendor |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
Thanks to Microsoft for reporting this vulnerability.
This document was written by Jason A Rafail.
Other Information
CVE IDs: | CVE-2004-0119 |
Severity Metric: | 30.12 |
Date Public: | 2004-04-13 |
Date First Published: | 2004-04-14 |
Date Last Updated: | 2004-04-14 15:23 UTC |
Document Revision: | 4 |