Oval Definition:oval:org.mitre.oval:def:3913
Revision Date:2011-10-24Version:45
Title:Windows Server 2003 (32-Bit) DUNZIP Integer Overflow
Description:Integer overflow in DUNZIP32.DLL for Microsoft Windows XP, Windows XP 64-bit Edition, Windows Server 2003, and Windows Server 2003 64-bit Edition allows remote attackers to execute arbitrary code via compressed (zipped) folders that involve an "unchecked buffer" and improper length validation.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2004-0575
Platform(s):Microsoft Windows Server 2003
Product(s):Compressed Folders
Definition Synopsis
  • Software section
  • Windows Server 2003 is installed
  • AND 32-Bit version of Windows is installed
  • AND the 32-bit version of zipfldr.dll is less than 6.0.3790.198
  • AND NOT the patch q873376 is installed (Hotfix key)
  • AND Configuration section
  • Compressed Folders with zipfldr.dll are enabled
  • BACK