Oval Definition:oval:org.mitre.oval:def:1222
Revision Date:2011-05-16Version:46
Title:MSDTC Invalid Memory Access Vulnerability (Win2K)
Description:Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 allows remote attackers to execute arbitrary code via a long fifth argument to the BuildContextW or BuildContext opcode, which triggers a bug in the NdrAllocate function, aka the MSDTC Invalid Memory Access Vulnerability.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2006-0034
Platform(s):Microsoft Windows 2000
Product(s):
Definition Synopsis
  • Windows 2000 Service Pack 4 (or later) is installed
  • Windows 2000 is installed
  • AND Win2K/XP/2003 service pack 4 (or later) is installed
  • AND the version of Msdtctm.dll is less than 2000.2.3535.0
  • BACK