RULE(RULE ID:711218)

Rule General Information
Release Date: 2017-08-18
Rule Name: Microsoft Windows XP and Server 2003 RDP Heap Buffer Overflow Vulnerability -1 (CVE-2017-0176)
Severity:
CVE ID:
Rule Protection Details
Description: A buffer overflow in Smart Card authentication code in gpkcsp.dll in Microsoft Windows XP through SP3 and Server 2003 through SP2 allows a remote attacker to execute arbitrary code on the target computer, provided that the computer is joined in a Windows domain and has Remote Desktop Protocol connectivity (or Terminal Services) enabled.
Impact: A buffer overflow vulnerability can be triggered by an attacker in the context of the vulnerable product. Further attacks include arbitrary code execution and denial of service.
Affected OS: Windows
Reference: SecurityFocusBID:98550
SecurityFocusBID:98752
https://blogs.technet.microsoft.com/msrc/2017/04/14/protecting-customers-and-evaluating-risk/
https://support.microsoft.com/en-us/help/4022747/security-update-for-windows-xp-and-windows-server-2003
Solutions
More advisories have been published on the website, please visit for more suggestions:
https://support.microsoft.com/en-us/help/4022747/security-update-for-windows-xp-and-windows-server-2003