Vulnerability CVE-2006-2379


Published: 2006-06-13   Modified: 2012-02-12

Description:
Buffer overflow in the TCP/IP Protocol driver in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote attackers to execute arbitrary code via unknown vectors related to IP source routing.

Type:

CWE-119

(Improper Restriction of Operations within the Bounds of a Memory Buffer)

CVSS2 => (AV:N/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
9.3/10
10/10
8.6/10
Exploit range
Attack complexity
Authentication
Remote
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Microsoft -> Windows 2000 
Microsoft -> Windows 2003 server 
Microsoft -> Windows nt 
Microsoft -> Windows xp 

 References:
http://securitytracker.com/id?1016290
http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/46702
http://www.kb.cert.org/vuls/id/722753
http://www.securityfocus.com/archive/1/438482/100/0/threaded
http://www.securityfocus.com/archive/1/438609/100/0/threaded
http://www.securityfocus.com/bid/18374
http://www.us-cert.gov/cas/techalerts/TA06-164A.html
http://www.vupen.com/english/advisories/2006/2329
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-032
https://exchange.xforce.ibmcloud.com/vulnerabilities/26834
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1483
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1585
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1712
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1776
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1787
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2018

Copyright 2024, cxsecurity.com

 

Back to Top