search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Microsoft Windows Terminal Services Advanced Client (TSAC) contains buffer overflow in process that handles input parameters

Vulnerability Note VU#276321

Original Release Date: 2002-08-27 | Last Revised: 2002-08-27

Overview

Microsoft Windows Terminal Services Advanced Client (TSAC) contains a remotely exploitable buffer overflow.

Description

The Microsoft Windows Terminal Services Advanced Client (TSAC) contains a remotely exploitable buffer overflow. This ActiveX control provides a way to deliver Terminal Services to a client using only a browser. This ActiveX control contains a buffer overflow in the code that processes input parameters.

Impact

A remote attacker can execute arbitrary code on a vulnerable system with the privileges of the victim.

Solution

Apply a patch.

Vendor Information

276321
 

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

This vulnerability was discovered by Ollie Whitehouse, of @Stake.

This document was written by Ian A Finlay.

Other Information

CVE IDs: CVE-2002-0726
Severity Metric: 24.00
Date Public: 2002-08-22
Date First Published: 2002-08-27
Date Last Updated: 2002-08-27 18:33 UTC
Document Revision: 10

Sponsored by CISA.