CVE-2007-3039 Information

Share on:

Description

Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4 Windows 2000 Professional SP4 and Windows XP SP2 allows attackers to execute arbitrary code via a long string in an opnum 0x06 RPC call to port 2103. NOTE: this is remotely exploitable on Windows 2000 Server.

Reference

http://secunia.com/advisories/28011 http://secunia.com/advisories/28051 http://www.securityfocus.com/archive/1/484891/100/0/threaded http://www.securityfocus.com/archive/1/485268/100/0/threaded http://www.securityfocus.com/bid/26797 http://www.securitytracker.com/id?1019077 http://www.us-cert.gov/cas/techalerts/TA07-345A.html http://www.vupen.com/english/advisories/2007/4181 http://www.zerodayinitiative.com/advisories/ZDI-07-076.html https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-065 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A4474 https://www.exploit-db.com/exploits/4745 https://www.exploit-db.com/exploits/4760 https://www.exploit-db.com/exploits/4934