| Microsoft Windows Knowledge Base Article 971468 update is not installed (WinMs10kb971468Update) |
|---|
| Vuln ID: | 55910 | |
|---|---|---|
| Risk Level: | High |
WinMs10kb971468Update |
| Platforms: | Microsoft Windows 2000: SP4, Microsoft Windows XP: SP2, Microsoft Windows Vista, Microsoft Windows Server 2003: SP2, Microsoft Windows Server 2003: SP2 Itanium, Microsoft Windows Server 2003: SP2 x64, Microsoft Windows Vista: x64, Microsoft Windows XP: SP2 x64 Professional, Microsoft Windows Vista: SP1, Microsoft Windows Vista: SP1 x64, Microsoft Windows Server 2008: Itanium, Microsoft Windows Server 2008: x32, Microsoft Windows Server 2008: x64, Microsoft Windows XP: SP3, Microsoft Windows Vista: SP2 x64, Microsoft Windows Vista: SP2, Microsoft Windows Server 2008: SP2 x32, Microsoft Windows Server 2008: SP2 x64, Microsoft Windows 7: x64, Microsoft Windows 7: x32, Microsoft Windows Server 2008: R2 x64, Microsoft Windows Server 2008: R2 Itanium, Microsoft Windows Server 2008: SP2 Itanium | |
| Description: | Microsoft Windows Knowledge Base Article 971468 update is not installed on the system, which could allow an attacker to exploit the following vulnerabilities: Microsoft Windows could allow a remote authenticated attacker to execute arbitrary code on the system, caused by the improper handling of malicious SMB responses within the pathname by the Microsoft Server Message Block (SMB) Protocol software. By sending a specially-crafted SMB packet to a computer connected to an SMB Server, a remote attacker could exploit this vulnerability to execute arbitrary code on the system. Microsoft Windows is vulnerable to a denial of service, caused by the improper handling of SMB packets by the Microsoft Server Message Block (SMB) Protocol software. By sending a specially-crafted SMB packet to a computer connected to an SMB Server, a remote attacker could exploit this vulnerability to corrupt memory and cause the system to stop responding. Microsoft Windows is vulnerable to a denial of service, caused by a NULL pointer dereference by the Microsoft Server Message Block (SMB) Protocol software when handling of SMB packets. By sending a specially-crafted SMB packet to a computer connected to an SMB Server, a remote attacker could exploit this vulnerability to cause the computer to stop responding. Microsoft Windows could allow a remote attacker to gain elevated privileges on the system, caused by the improper handling of NTLM authentication attempts by the Microsoft Server Message Block (SMB) Protocol software. By sending an overly large amount of authentication requests to the SMB server, a remote attacker could exploit this vulnerability to access the SMB service to gain elevated privileges on the system. |
|
| Remedy: | Apply the appropriate patch for your system, as listed in Microsoft Security Bulletin MS10-012. See References. |
|
| False Positives: | ||
| False Negatives: | ||
| Required Permission: | Windows login | |
| Additional Information: | ||
| References: | IBM Internet Security Systems X-Force Database IBM Internet Security Systems X-Force Database IBM Internet Security Systems X-Force Database IBM Internet Security Systems X-Force Database Microsoft Security Bulletin MS10-012 ISS X-Force CVE CVE-2010-0231 |
|
![]() Know Your Risks |
![]() Common Vulnerabilties & Exposures |