MS.WINS.ECommEndDlg.Input.Validation.Error
Description
This indicates an attack attempt against an Input Validation Error vulnerability in Microsoft WINS.
The vulnerability is caused by an error when the vulnerable software handles a malicious "ECommEndDlg" method. It allows a remote attacker to execute arbitrary code via sending a crafted WINS replication packet.
Affected Products
Windows Server 2003 SP0, SP1 and SP2.
Windows Server 2003 x64 Edition SP2.
Windows Server 2003 SP2 for Itanium-based Systems.
Windows Server 2008 SP2.
Windows Server 2008 x64 Edition SP2.
Windows Server 2008 R2 for x64-based Systems.
Impact
System Compromise: Remote attackers can gain control of vulnerable systems.
Recommended Actions
Apply the latest update from the vendor.
Windows Server 2003 SP0, SP1 and SP2.
http://www.microsoft.com/downloads/details.aspx?familyid=1e6ac3b2-752e-49a0-84e5-5a8dfe955299
Windows Server 2003 x64 Edition SP2.
http://www.microsoft.com/downloads/details.aspx?familyid=f9378339-c58e-4e84-9427-85aeb35b0d99
Windows Server 2003 SP2 for Itanium-based Systems.
http://www.microsoft.com/downloads/details.aspx?familyid=c35c71a8-13b4-47a6-9763-06f6f65327b1
Windows Server 2008 SP2.
http://www.microsoft.com/downloads/details.aspx?familyid=a9039660-3cc2-470d-a0a5-a70f78074495
Windows Server 2008 x64 Edition SP2.
http://www.microsoft.com/downloads/details.aspx?familyid=5ea78a9b-b1f7-4e94-b69e-c984e1622ae9
Windows Server 2008 R2 for x64-based Systems.
http://www.microsoft.com/downloads/details.aspx?familyid=f58cf343-946c-4e74-bd9c-40ac934a4986
Telemetry
Coverage
IPS (Regular DB) | |
IPS (Extended DB) |