10

CVE-2009-0568

The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly maintain its internal state, which allows remote attackers to overwrite arbitrary memory locations via a crafted RPC message that triggers incorrect pointer reading, related to "IDL interfaces containing a non-conformant varying array" and FC_SMVARRAY, FC_LGVARRAY, FC_VARIABLE_REPEAT, and FC_VARIABLE_OFFSET, aka "RPC Marshalling Engine Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 2000 Update sp4
Microsoft ≫ Windows 2003 Server Update sp2 HwPlatform itanium
Microsoft ≫ Windows 2003 Server Update sp2 HwPlatform x64
Microsoft ≫ Windows Server Version 2008 HwPlatform itanium
Microsoft ≫ Windows Server Version 2008 Edition sp2 HwPlatform itanium
Microsoft ≫ Windows Server 2008 HwPlatform x64
Microsoft ≫ Windows Server 2008 HwPlatform x86
Microsoft ≫ Windows Server 2008 Update sp2 HwPlatform x64
Microsoft ≫ Windows Server 2008 Update sp2 HwPlatform x86
Microsoft ≫ Windows Vista HwPlatform x64
Microsoft ≫ Windows Vista Update sp1
Microsoft ≫ Windows Vista Update sp2
Microsoft ≫ Windows Vista Version -
Microsoft ≫ Windows Xp Update sp2
Microsoft ≫ Windows Xp Update sp2 HwPlatform x64
Microsoft ≫ Windows Xp Update sp3
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 32.39% 0.981
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://www.us-cert.gov/cas/techalerts/TA09-160A.html
Third Party Advisory
US Government Resource
http://blogs.technet.com/srd/archive/2009/06/09/ms09-026-how-a-developer-can-know-if-their-rpc-interface-is-affected.aspx
Vendor Advisory
http://osvdb.org/54936
Broken Link
http://www.securityfocus.com/bid/35219
Third Party Advisory
VDB Entry
http://www.securitytracker.com/id?1022357
Third Party Advisory
VDB Entry
http://www.vupen.com/english/advisories/2009/1545
Third Party Advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-026
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6227
Third Party Advisory