NT Spoolss.exe Buffer Overflow Vulnerabilities
BID:768
Info
NT Spoolss.exe Buffer Overflow Vulnerabilities
| Bugtraq ID: | 768 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Nov 04 1999 12:00AM |
| Updated: | Nov 04 1999 12:00AM |
| Credit: | Posted to Bugtraq by Marc of eEye <[email protected]> on November 4, 1999. |
| Vulnerable: |
Microsoft Windows NT 4.0 SP6 Microsoft Windows NT 4.0 SP5 Microsoft Windows NT 4.0 SP4 Microsoft Windows NT 4.0 SP3 Microsoft Windows NT 4.0 SP2 Microsoft Windows NT 4.0 SP1 Microsoft Windows NT 4.0 |
| Not Vulnerable: | |
Discussion
NT Spoolss.exe Buffer Overflow Vulnerabilities
Spoolss.exe, AKA the spooler service, which handles all print requests for the NT operating system, has a number of APIs with unchecked buffers. Some of these can only be executed by Power Users or Administrators, but some are accessible to all authenticated users. Many of the overflows will write directly into the EIP register, meaning that an exploit could be created to run arbitrary code as SYSTEM.
Spoolss.exe, AKA the spooler service, which handles all print requests for the NT operating system, has a number of APIs with unchecked buffers. Some of these can only be executed by Power Users or Administrators, but some are accessible to all authenticated users. Many of the overflows will write directly into the EIP register, meaning that an exploit could be created to run arbitrary code as SYSTEM.
Exploit / POC
NT Spoolss.exe Buffer Overflow Vulnerabilities
x
x
References
NT Spoolss.exe Buffer Overflow Vulnerabilities
References:
References: