CVE-2006-4688
🟡 Monitoruj
Przepełnienie bufora w Client Service for NetWare umożliwia zdalne wykonanie kodu.
CVSS
7.5
EPSS
82.8%
Exploit
none
Vendor
microsoft
Opis źródłowy (NVD)
Buffer overflow in Client Service for NetWare (CSNW) in Microsoft Windows 2000 SP4, XP SP2, and Server 2003 up to SP1 allows remote attackers to execute arbitrary code via crafted messages, aka "Client Service for NetWare Memory Corruption Vulnerability."
buffer-overflow
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 7.5 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 82.8% |
| Opublikowano (NVD) | 2006-11-14 22:07:00 UTC |
| Ostatnia modyfikacja (NVD) | 2026-04-23 00:35:47 UTC |
Referencje
- http://secunia.com/advisories/22866 (secure@microsoft.com) [Patch]
- http://securitytracker.com/id?1017224 (secure@microsoft.com)
- http://www.securityfocus.com/archive/1/451844/100/0/threaded (secure@microsoft.com)
- http://www.securityfocus.com/bid/21023 (secure@microsoft.com)
- http://www.us-cert.gov/cas/techalerts/TA06-318A.html (secure@microsoft.com) [US Government Resource]
- http://www.vupen.com/english/advisories/2006/4504 (secure@microsoft.com)
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-066 (secure@microsoft.com)
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29952 (secure@microsoft.com)
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A404 (secure@microsoft.com)