Microsoft Windows DDEShare Buffer Overflow Vulnerability
BID:11638
Info
Microsoft Windows DDEShare Buffer Overflow Vulnerability
| Bugtraq ID: | 11638 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 09 2004 12:00AM |
| Updated: | Nov 09 2004 12:00AM |
| Credit: | Discovery of this vulnerability is credited to Jack C <[email protected]>. |
| Vulnerable: |
Microsoft Windows XP Professional SP2 Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Home SP2 Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Discussion
Microsoft Windows DDEShare Buffer Overflow Vulnerability
A buffer overflow vulnerability is reported to affect the Microsoft Windows 'ddeshare.exe' utility.
Although unconfirmed it is conjectured that a remote attacker may potentially exploit this condition to execute arbitrary code in the context of a user that is employing the affected utility to process a malicious remote DDE share name.
A buffer overflow vulnerability is reported to affect the Microsoft Windows 'ddeshare.exe' utility.
Although unconfirmed it is conjectured that a remote attacker may potentially exploit this condition to execute arbitrary code in the context of a user that is employing the affected utility to process a malicious remote DDE share name.
Exploit / POC
Microsoft Windows DDEShare Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Windows DDEShare Buffer Overflow Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Windows DDEShare Buffer Overflow Vulnerability
References:
References:
- Technet Security (Microsoft)
- BoF in Windows 2000: ddeshare.exe (Jack C
)