CVE-2006-4691
🔴 Łataj teraz
Przepełnienie bufora w funkcji NetpManageIPCConnect w usłudze Workstation pozwala na zdalne wykonanie kodu.
CVSS
10.0
EPSS
88.9%
Exploit
none
Vendor
microsoft
Opis źródłowy (NVD)
Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname.
buffer-overflow
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 10.0 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 88.9% |
| Opublikowano (NVD) | 2006-11-14 21:07:00 UTC |
| Ostatnia modyfikacja (NVD) | 2026-04-23 00:35:47 UTC |
Referencje
- http://research.eeye.com/html/advisories/published/AD20061114.html (secure@microsoft.com)
- http://secunia.com/advisories/22883 (secure@microsoft.com) [Patch, Vendor Advisory]
- http://securitytracker.com/id?1017221 (secure@microsoft.com)
- http://www.kb.cert.org/vuls/id/778036 (secure@microsoft.com) [US Government Resource]
- http://www.securityfocus.com/archive/1/451588/100/0/threaded (secure@microsoft.com)
- http://www.securityfocus.com/bid/20985 (secure@microsoft.com)
- http://www.us-cert.gov/cas/techalerts/TA06-318A.html (secure@microsoft.com) [US Government Resource]
- http://www.vupen.com/english/advisories/2006/4508 (secure@microsoft.com)
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-070 (secure@microsoft.com)
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29948 (secure@microsoft.com)
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A607 (secure@microsoft.com)
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A908 (secure@microsoft.com)