Vulnerabilities > CVE-2006-1314 - Remote Heap Buffer Overflow vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
Heap-based buffer overflow in the Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to execute arbitrary code via crafted first-class Mailslot messages that triggers memory corruption and bypasses size restrictions on second-class Mailslot messages.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 9 |
Exploit-Db
description | MS Windows Mailslot Ring0 Memory Corruption Exploit (MS06-035). CVE-2006-1314,CVE-2006-1315,CVE-2006-3942. Dos exploit for windows platform |
file | exploits/windows/dos/2057.c |
id | EDB-ID:2057 |
last seen | 2016-01-31 |
modified | 2006-07-21 |
platform | windows |
port | |
published | 2006-07-21 |
reporter | cocoruder |
source | https://www.exploit-db.com/download/2057/ |
title | Microsoft Windows - Mailslot Ring0 Memory Corruption Exploit MS06-035 |
type | dos |
Nessus
NASL family Windows : Microsoft Bulletins NASL id SMB_NT_MS06-063.NASL description The remote host has a memory corruption vulnerability in the last seen 2020-06-01 modified 2020-06-02 plugin id 22536 published 2006-10-10 reporter This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/22536 title MS06-063: Vulnerability in Server Service Could Allow Denial of Service (923414) NASL family Windows : Microsoft Bulletins NASL id SMB_NT_MS06-035.NASL description The remote host is vulnerable to heap overflow in the last seen 2020-06-01 modified 2020-06-02 plugin id 22029 published 2006-07-11 reporter This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/22029 title MS06-035: Vulnerability in Server Service Could Allow Remote Code Execution (917159) NASL family Windows NASL id SMB_KB917159.NASL description The remote host is vulnerable to heap overflow in the last seen 2020-06-01 modified 2020-06-02 plugin id 22034 published 2006-07-12 reporter This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/22034 title MS06-035: Vulnerability in Server Service Could Allow Remote Code Execution (917159) (uncredentialed check)
Oval
accepted | 2011-05-09T04:01:37.674-04:00 | ||||||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||||||
contributors |
| ||||||||||||||||||||||||
definition_extensions |
| ||||||||||||||||||||||||
description | Heap-based buffer overflow in the Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to execute arbitrary code via crafted first-class Mailslot messages that triggers memory corruption and bypasses size restrictions on second-class Mailslot messages. | ||||||||||||||||||||||||
family | windows | ||||||||||||||||||||||||
id | oval:org.mitre.oval:def:600 | ||||||||||||||||||||||||
status | accepted | ||||||||||||||||||||||||
submitted | 2006-07-25T12:05:33 | ||||||||||||||||||||||||
title | Mailslot Heap Overflow Vulnerability | ||||||||||||||||||||||||
version | 43 |
References
- http://secunia.com/advisories/21007
- http://securityreason.com/securityalert/1212
- http://www.kb.cert.org/vuls/id/189140
- http://www.osvdb.org/27154
- http://www.securityfocus.com/archive/1/439773/100/0/threaded
- http://www.securityfocus.com/bid/18863
- http://www.tippingpoint.com/security/advisories/TSRT-06-02.html
- http://www.us-cert.gov/cas/techalerts/TA06-192A.html
- http://www.vupen.com/english/advisories/2006/2753
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-035
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26818
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A600