Vulnerability CVE-2005-2119


Published: 2005-10-12   Modified: 2012-02-12

Description:
The MIDL_user_allocate function in the Microsoft Distributed Transaction Coordinator (MSDTC) proxy (MSDTCPRX.DLL) allocates a 4K page of memory regardless of the required size, which allows attackers to overwrite arbitrary memory locations using an incorrect size value that is provided to the NdrAllocate function, which writes management data to memory outside of the allocated buffer.

See advisories in our WLB2 database:
Topic
Author
Date
High
Microsoft Distributed Transaction Coordinator Memory Modification Vulnerability
Fang Xing
12.10.2005

Type:

CWE-Other

CVSS2 => (AV:N/AC:L/Au:N/C:N/I:P/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5/10
2.9/10
10/10
Exploit range
Attack complexity
Authentication
Remote
Low
No required
Confidentiality impact
Integrity impact
Availability impact
None
Partial
None
Affected software
Microsoft -> Windows 2000 
Microsoft -> Windows 2003 server 
Microsoft -> Windows xp 

 References:
http://securityreason.com/securityalert/73
http://securitytracker.com/id?1015037
http://support.avaya.com/elmodocs2/security/ASA-2005-214.pdf
http://www.eeye.com/html/research/advisories/AD20051011b.html
http://www.kb.cert.org/vuls/id/180868
http://www.securityfocus.com/bid/15056
http://www.us-cert.gov/cas/techalerts/TA05-284A.html
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-051
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1071
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1452
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A551

Copyright 2024, cxsecurity.com

 

Back to Top