[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247768

 
 

909

 
 

194555

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

Remote code execution vulnerability is present in SMB Client Could in Microsoft Windows - MS11-019

ID: oval:org.secpod.oval:def:1040Date: (C)2011-05-23   (M)2023-12-14
Class: PATCHFamily: windows




The host is missing a Critical security update according to Microsoft security bulletin, MS11-019. The update is required to fix remote code execution vulnerability in Microsoft Windows. The flaws are present in the SMB Client Could which fails to handle specially crafted SMB response to a client-initiated SMB request and fails to parse malformed browser message through Common Internet File System (CIFS) Browser Protocol. Successful exploitation allows an attacker to execute arbitrary code and take complete control of an affected system.

Platform:
Microsoft Windows 7
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Vista
Microsoft Windows XP
Reference:
MS11-019
CVE-2011-0654
CVE-2011-0660
CVE    2
CVE-2011-0654
CVE-2011-0660
CPE    38
cpe:/o:microsoft:windows_server_2008:r2:sp1:x64
cpe:/o:microsoft:windows_server_2008:::x86
cpe:/o:microsoft:windows_7:::x64
cpe:/o:microsoft:windows_server_2008:r2:sp1:itanium
...
XCCDF    8
xccdf_com.secpod_benchmark_microsoft-windows-server-2008
xccdf_com.secpod_benchmark_microsoft-windows-server-2003
xccdf_com.secpod_benchmark_microsoft-windows-7
xccdf_scaprepo.com_benchmark_microsoft-windows-server-2003
...

© SecPod Technologies