Overview
A vulnerability in the way Microsoft Workstation Service parses malformed network messages may lead to execution of arbitrary code.
Description
Microsoft Workstation Service contains a vulnerability that could be exploited when Workstation Service attempts to parse specially crafted network messages. According to Microsoft Security Bulletin MS06-070: On Windows 2000 Service Pack 4 any anonymous user who could deliver a specially crafted message to the affected system could try to exploit this vulnerability. On Windows XP Service Pack 2 the attack could only be successfully performed by a user with Administrator privileges. |
Impact
A remote, unauthenticated attacker may be able to execute arbitrary code or cause a denial-of-service condition. |
Solution
Update |
Workarounds
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was reported in Microsoft Security Bulletin MS06-070. Microsoft credits eEye for reporting this issue.
This document was written by Chris Taschner.
Other Information
CVE IDs: | CVE-2006-4691 |
Severity Metric: | 18.63 |
Date Public: | 2006-11-14 |
Date First Published: | 2006-11-15 |
Date Last Updated: | 2006-11-21 17:12 UTC |
Document Revision: | 20 |