Vulnerabilities > CVE-2006-1315 - Unspecified vulnerability in Microsoft Server Service
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN Summary
The Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to obtain sensitive information via crafted requests that leak information in SMB buffers, which are not properly initialized, aka "SMB Information Disclosure Vulnerability."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | MS Windows Mailslot Ring0 Memory Corruption Exploit (MS06-035). CVE-2006-1314,CVE-2006-1315,CVE-2006-3942. Dos exploit for windows platform |
file | exploits/windows/dos/2057.c |
id | EDB-ID:2057 |
last seen | 2016-01-31 |
modified | 2006-07-21 |
platform | windows |
port | |
published | 2006-07-21 |
reporter | cocoruder |
source | https://www.exploit-db.com/download/2057/ |
title | Microsoft Windows - Mailslot Ring0 Memory Corruption Exploit MS06-035 |
type | dos |
Nessus
NASL family Windows : Microsoft Bulletins NASL id SMB_NT_MS06-063.NASL description The remote host has a memory corruption vulnerability in the last seen 2020-06-01 modified 2020-06-02 plugin id 22536 published 2006-10-10 reporter This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/22536 title MS06-063: Vulnerability in Server Service Could Allow Denial of Service (923414) NASL family Windows : Microsoft Bulletins NASL id SMB_NT_MS06-035.NASL description The remote host is vulnerable to heap overflow in the last seen 2020-06-01 modified 2020-06-02 plugin id 22029 published 2006-07-11 reporter This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/22029 title MS06-035: Vulnerability in Server Service Could Allow Remote Code Execution (917159) NASL family Windows NASL id SMB_KB917159.NASL description The remote host is vulnerable to heap overflow in the last seen 2020-06-01 modified 2020-06-02 plugin id 22034 published 2006-07-12 reporter This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. source https://www.tenable.com/plugins/nessus/22034 title MS06-035: Vulnerability in Server Service Could Allow Remote Code Execution (917159) (uncredentialed check)
Oval
accepted | 2011-05-09T04:01:29.780-04:00 | ||||||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||||||
contributors |
| ||||||||||||||||||||||||
definition_extensions |
| ||||||||||||||||||||||||
description | The Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to obtain sensitive information via crafted requests that leak information in SMB buffers, which are not properly initialized, aka "SMB Information Disclosure Vulnerability." | ||||||||||||||||||||||||
family | windows | ||||||||||||||||||||||||
id | oval:org.mitre.oval:def:3 | ||||||||||||||||||||||||
status | accepted | ||||||||||||||||||||||||
submitted | 2006-07-25T12:05:33 | ||||||||||||||||||||||||
title | SMB Information Disclosure Vulnerability | ||||||||||||||||||||||||
version | 43 |
References
- http://secunia.com/advisories/21007
- http://secunia.com/advisories/21007
- http://securitytracker.com/id?1016467
- http://securitytracker.com/id?1016467
- http://www.kb.cert.org/vuls/id/333636
- http://www.kb.cert.org/vuls/id/333636
- http://www.osvdb.org/27155
- http://www.osvdb.org/27155
- http://www.securityfocus.com/archive/1/439881/100/0/threaded
- http://www.securityfocus.com/archive/1/439881/100/0/threaded
- http://www.securityfocus.com/bid/18891
- http://www.securityfocus.com/bid/18891
- http://www.vupen.com/english/advisories/2006/2753
- http://www.vupen.com/english/advisories/2006/2753
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-035
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-035
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26820
- https://exchange.xforce.ibmcloud.com/vulnerabilities/26820
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3