10
CVE-2009-0568
- EPSS 32.39%
- Veröffentlicht 10.06.2009 18:00:00
- Zuletzt bearbeitet 16.06.2026 23:05:19
- Erkennungen
The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly maintain its internal state, which allows remote attackers to overwrite arbitrary memory locations via a crafted RPC message that triggers incorrect pointer reading, related to "IDL interfaces containing a non-conformant varying array" and FC_SMVARRAY, FC_LGVARRAY, FC_VARIABLE_REPEAT, and FC_VARIABLE_OFFSET, aka "RPC Marshalling Engine Vulnerability."
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows 2000 Update sp4
Microsoft ≫ Windows 2003 Server Update sp2
Microsoft ≫ Windows 2003 Server Update sp2 HwPlatform itanium
Microsoft ≫ Windows 2003 Server Update sp2 HwPlatform x64
Microsoft ≫ Windows Server Version 2008 HwPlatform itanium
Microsoft ≫ Windows Server Version 2008 Edition sp2 HwPlatform itanium
Microsoft ≫ Windows Server 2008 HwPlatform x64
Microsoft ≫ Windows Server 2008 HwPlatform x86
Microsoft ≫ Windows Server 2008 Update sp2 HwPlatform x64
Microsoft ≫ Windows Server 2008 Update sp2 HwPlatform x86
Microsoft ≫ Windows Vista HwPlatform x64
Microsoft ≫ Windows Vista Update sp1
Microsoft ≫ Windows Vista Update sp2
Microsoft ≫ Windows Vista Version -
Microsoft ≫ Windows Xp Update sp2
Microsoft ≫ Windows Xp Update sp2 HwPlatform x64
Microsoft ≫ Windows Xp Update sp3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 32.39% | 0.981 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
http://www.us-cert.gov/cas/techalerts/TA09-160A.html
http://blogs.technet.com/srd/archive/2009/06/09/ms09-026-how-a-developer-can-know-if-their-rpc-interface-is-affected.aspx
http://osvdb.org/54936
http://www.securityfocus.com/bid/35219
http://www.securitytracker.com/id?1022357
http://www.vupen.com/english/advisories/2009/1545
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-026
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6227