|
|||
Rule General Information |
---|
Release Date: | 2020-06-30 | |
Rule Name: | Microsoft Windows WINS Service Integer Overflow Vulnerability -2 (CVE-2009-1924) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | Integer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 allows remote WINS replication partners to execute arbitrary code via crafted data structures in a packet, aka "WINS Integer Overflow Vulnerability." | |
Impact: | An attacker can exploit the affected software with a integer overflow vulnerability. Successful exploit leads to execute arbitrary code, and failed exploit may disturb the software logic and cause denial of service. | |
Affected OS: | Windows | |
Reference: | MicrosoftSecurityBulletin:ms09-039 http://www.us-cert.gov/cas/techalerts/TA09-223A.html https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6354 |
|
Solutions |
---|
The vendors have released upgrade patches to fix vulnerabilities, please visit: http://www.microsoft.com/technet/security/bulletin/ms09-039.mspx?pf=true |