|
|
|
|
| |
Credit:
The information has been provided by Cody Pierce.
The original article can be found at: http://dvlabs.tippingpoint.com/advisory/TPTI-09-06
|
| |
Vulnerable Systems:
* Microsoft Windows Server 2008
* Microsoft Windows Vista
* Microsoft Windows Server 2003
* Microsoft Windows XP SP3
The specific flaw exists in the Workstation RPC Service. When handling the arguments for the NetrGetJoinInformation function, memory is improperly freed and can lead to remote code execution. Successful exploitation can lead to a remote system compromise under SYSTEM credentials.
Patch Availability:
Microsoft has issued an update to correct this vulnerability. More details can be found at:
http://www.microsoft.com/technet/security/bulletin/MS09-041.mspx
CVE Information:
CVE-2009-1544
Disclosure Timeline:
2009-05-11 - Vulnerability reported to vendor
2009-08-11 - Coordinated public release of advisory
|
|
|
|
|