MS.Windows.SMB.Handlers.Remote.Buffer.Overflow

description-logoDescription

This indicates a possible attempt to exploit a remote buffer-overflow vulnerability in Microsoft's SMB implementation.
The vulnerability is caused by an error when the vulnerable software handles a malicious Trans or Trans2 command with a malformed "file name". It allows a remote attacker to execute arbitrary code via sending a crafted SMB response packet.

affected-products-logoAffected Products

Microsoft Windows 2000 SP3 and Microsoft Windows 2000 SP4
Microsoft Windows XP SP1 and Microsoft Windows XP SP2
Microsoft Windows XP 64-Bit Edition SP1 (Itanium)
Microsoft Windows XP 64-Bit Edition Version 2003 (Itanium)
Microsoft Windows Server 2003
Microsoft Windows Server 2003 for Itanium-based Systems

Impact logoImpact

System compromise: Arbitrary code execution

recomended-action-logoRecommended Actions

Microsoft Security Bulletin MS05-011 was released to address this issue:
http://www.microsoft.com/technet/security/bulletin/MS05-011.mspx

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)