Oval Definition:oval:org.mitre.oval:def:1477
Revision Date:2011-05-16Version:46
Title:MSDTC Invalid Memory Access Vulnerability (Server 2003)
Description:Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 allows remote attackers to execute arbitrary code via a long fifth argument to the BuildContextW or BuildContext opcode, which triggers a bug in the NdrAllocate function, aka the MSDTC Invalid Memory Access Vulnerability.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2006-0034
Platform(s):Microsoft Windows Server 2003
Product(s):
Definition Synopsis
  • Windows Server 2003 is installed
  • AND NOT Win2K/XP/2003 is patched
  • AND the version of Msdtctm.dll is less than 2001.12.4720.480
  • BACK