Vulnerabilities > CVE-2002-1214 - Unspecified vulnerability in Microsoft products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
Buffer overflow in Microsoft PPTP Service on Windows XP and Windows 2000 allows remote attackers to cause a denial of service (hang) and possibly execute arbitrary code via a certain PPTP packet with malformed control data.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 11 |
Metasploit
description | This module exploits a kernel based overflow when sending abnormal PPTP Control Data packets to Microsoft Windows 2000 SP0-3 and XP SP0-1 based PPTP RAS servers (Remote Access Services). Kernel memory is overwritten resulting in a BSOD. Code execution may be possible however this module is only a DoS. |
id | MSF:AUXILIARY/DOS/PPTP/MS02_063_PPTP_DOS |
last seen | 2020-04-11 |
modified | 2017-11-08 |
published | 2009-07-03 |
references | https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2002-1214 |
reporter | Rapid7 |
source | https://github.com/rapid7/metasploit-framework/blob/master//modules/auxiliary/dos/pptp/ms02_063_pptp_dos.rb |
title | MS02-063 PPTP Malformed Control Data Kernel Denial of Service |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS02-063.NASL |
description | The remote version of Windows contains a flaw in its PPTP implementation. If the remote host is configured to act as a PPTP server, a remote attacker can send a specially crafted packet to corrupt the kernel memory and crash the remote system. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11178 |
published | 2002-11-28 |
reporter | This script is Copyright (C) 2002-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11178 |
title | MS02-063: Unchecked Buffer in PPTP Implementation Could Enable DOS Attacks (329834) |
code |
|