MS.RPC.WKSSVC.Buffer.Overflow

description-logoDescription

This indicates an attack attempt against a buffer overflow vulnerability in Microsoft Windows Workstation (WKSSVC.DLL) service.
The vulnerability is caused by improper bounds checking in the NetAddAlternateComputerName API. By sending a specially crafted RPC request to the WKSSVC RPC interface, a remote attacker could overflow a buffer and
execute arbitrary code on a vulnerable system.

affected-products-logoAffected Products

Windows 2000 SP4
Windows XP SP1 and earlier service packs

Impact logoImpact

System Compromise: Remote attackers can gain control of vulnerable systems.

recomended-action-logoRecommended Actions

Apply patch, available from the web site:
http://www.microsoft.com/technet/security/Bulletin/MS03-049.mspx

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)