.:[ packet storm ]:.
                               
reconnaissance for both sides
reconnaissance for both sides

 ///  File Name:TPTI-08-07.txt
Description:
A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows running the Message Queuing service (mqsvc.exe). User interaction is not required to exploit this vulnerability. The specific flaw exists in the parsing of an RPC request to the Message Queuing Service (mqsvc.exe). By sending a specially crafted RPC request a heap calculation can be controlled and later overflowed during an unchecked string copy operation. By sending a similar request memory can be disclosed to the attacker. Exploitation of the heap overflow leads to full access of the affected system under the SYSTEM context.
Author:Cody Pierce
Homepage:http://www.tippingpoint.com/
File Size:1804
Related CVE(s):CVE-2008-3479
Last Modified:Oct 15 02:32:19 2008
MD5 Checksum:2faeb00e2cd02ca785c27c636eb3497d

 .:. Back