| |||||||||||||
| Test ID: | 1.3.6.1.4.1.25623.1.0.900224 |
| Category: | Windows : Microsoft Bulletins |
| Title: | Message Queuing Remote Code Execution Vulnerability (951071) |
| Summary: | Check for the Hotfix and version of Message Queue component |
| Description: | MS08-065 Overview: This host is missing important security update according to Microsoft Bulletin MS08-065. Vulnerability Insight: The flaw exists due to a boundary error when parsing RPC requests to the Message Queuing (MSMQ). Impact: Successful exploitation could allow remote code execution by sending a specially crafted RPC request and can take complete control of an affected system. Impact Level: System Affected Software/OS: Microsoft Windows 2000 Service Pack 4 and prior. Fix: Run Windows Update and update the listed hotfixes or download and update mentioned hotfixes in the advisory from the below link. http://www.microsoft.com/technet/security/Bulletin/MS08-065.mspx References: http://www.microsoft.com/technet/security/Bulletin/MS08-065.mspx |
| Cross-Ref: |
BugTraq ID: 31637 Common Vulnerability Exposure (CVE) ID: CVE-2008-3479 http://dvlabs.tippingpoint.com/advisory/TPTI-08-07 HPdes Security Advisory: HPSBST02379 http://marc.info/?l=bugtraq&m=122479227205998&w=2 HPdes Security Advisory: SSRT080143 Microsoft Security Bulletin: MS08-065 http://www.microsoft.com/technet/security/Bulletin/MS08-065.mspx Cert/CC Advisory: TA08-288A http://www.us-cert.gov/cas/techalerts/TA08-288A.html http://www.securityfocus.com/bid/31637 http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:5998 http://www.vupen.com/english/advisories/2008/2816 http://www.securitytracker.com/id?1021052 http://secunia.com/advisories/32260 XForce ISS Database: win-ms08kb951071-update(45538) http://xforce.iss.net/xforce/xfdb/45538 XForce ISS Database: win-msmq-rpc-code-execution(45537) http://xforce.iss.net/xforce/xfdb/45537 |
| Copyright | Copyright (C) 2008 SecPod |
| This is only one of 32582 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |
|