Oval Definition:
oval:org.mitre.oval:def:12634
Revision Date
:
2011-10-31
Version
:
44
Title
:
WINS Local Elevation of Privilege Vulnerability
Description
:
WINS in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges by sending crafted packets over the loopback interface, aka "WINS Local Elevation of Privilege Vulnerability."
Family
:
windows
Class
:
vulnerability
Status
:
ACCEPTED
Reference(s)
:
CVE-2011-1984
Platform(s)
:
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Product(s)
:
Definition Synopsis
Vulnerable Windows Server 2003 x86/x64/ia64 SP2
Windows Server 2003 x86/x64/ia64 SP2
Microsoft Windows Server 2003 SP2 (x86) is installed
OR
Microsoft Windows Server 2003 SP2 (x64) is installed
OR
Microsoft Windows Server 2003 (ia64) SP2 is installed
AND
the version of wins.exe is less than 5.2.3790.4893
OR
Vulnerable Windows Server 2008 x86/x64 SP2
Windows Server 2008 x86/x64 SP2
Microsoft Windows Server 2008 (32-bit) Service Pack 2 is installed
OR
Microsoft Windows Server 2008 x64 Edition Service Pack 2 is installed
AND
GDR or LDR Service branch
the version of wins.exe is less than 6.0.6002.18501
OR
LDR
the version of wins.exe is less than 6.0.6002.22693
AND
the version of wins.exe is greater than or equal 6.0.6002.22000
OR
Vulnerable Windows Server 2008 R2 x64
Microsoft Windows Server 2008 R2 x64 Edition is installed
AND
GDR or LDR Service branch
the version of wins.exe is less than 6.1.7600.16861
OR
LDR
the version of wins.exe is less than 6.1.7600.21024
AND
the version of wins.exe is greater than or equal 6.1.7600.21000
OR
Vulnerable Windows Server 2008 R2 x64 SP1
Microsoft Windows Server 2008 R2 x64 Service Pack 1 is installed
AND
GDR or LDR Service branch
the version of wins.exe is less than 6.1.7601.17664
OR
LDR
the version of wins.exe is less than 6.1.7601.21786
AND
the version of wins.exe is greater than or equal 6.1.7601.21000
BACK