Oval Definition:oval:org.mitre.oval:def:3071
Revision Date:2008-03-24Version:45
Title:Windows NT Program Group Converter Buffer Overflow
Description:Buffer overflow in the Windows Program Group Converter (grpconv.exe) may allow remote attackers to execute arbitrary code via a shell: URL with a long filename and a .grp extension, which is not properly handled when the shell capability launches grpconv.exe.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2004-0572
Platform(s):Microsoft Windows NT
Product(s):Program Group Converter
Definition Synopsis
  • Microsoft Windows NT is installed
  • AND a vulnerable version of grpconv.exe exists on NT
  • NT Server and grpconv.exe less than 4.0.1381.7286
  • Windows NT server product option
  • this is an NT Server (stand-alone)
  • OR this is an NT Server (domain controller)
  • AND the version of grpconv.exe (system32) is less than 4.0.1381.7286
  • OR NT Terminal Server and grpconv.exe less than 4.0.1381.33577
  • this is an NT Terminal Server
  • AND the version of grpconv.exe (system32) is less than 4.0.1381.33577
  • AND NOT the patch q841356 is installed (Hotfix key)
  • BACK