Oval Definition:oval:org.mitre.oval:def:6093
Revision Date:2011-11-07Version:45
Title:Server Service Vulnerability
Description:The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overflow during path canonicalization, as exploited in the wild by Gimmiv.A in October 2008, aka "Server Service Vulnerability."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2008-4250
Platform(s):Microsoft Windows 2000
Microsoft Windows Server 2003
Microsoft Windows Server 2008
Microsoft Windows Vista
Microsoft Windows XP
Product(s):
Definition Synopsis
  • Check for vulnerable Windows 2000 SP4 and Netapi32.dll version
  • Microsoft Windows 2000 SP4 or later is installed
  • AND Netapi32.dll version is less than 5.0.2195.7203
  • OR Check for vulnerable Windows XP (x86) SP2 and Netapi32.dll version
  • Microsoft Windows XP (x86) SP2 is installed
  • AND Netapi32.dll version is less than 5.1.2600.3462
  • OR Check for vulnerable Windows XP (x86) SP3 and Netapi32.dll version
  • Microsoft Windows XP (x86) SP3 is installed
  • AND Netapi32.dll version is less than 5.1.2600.5694
  • OR Check for vulnerable Windows Server 2003 SP1 (x86)/(x64)/(IA-64)/XP x64 SP1 and Netapi32.dll version
  • Check for vulnerable Windows Server 2003 SP1 (x86)/(x64)/(IA-64)/XP x64 SP1
  • Microsoft Windows Server 2003 SP1 (x86) is installed
  • OR Microsoft Windows Server 2003 SP1 (x64) is installed
  • OR Microsoft Windows XP Professional x64 Edition SP1 is installed
  • OR Microsoft Windows Server 2003 SP1 for Itanium is installed
  • AND Netapi32.dll version is less than 5.2.3790.3229
  • OR Check for vulnerable Windows Server 2003 SP2 (x86)/(x64)/(IA-64)/XP x64 SP2 and Netapi32.dll version
  • Check for vulnerable Windows Server 2003 SP2 (x86)/(x64)/(IA-64)/XP x64 SP2
  • Microsoft Windows Server 2003 SP2 (x86) is installed
  • OR Microsoft Windows Server 2003 SP2 (x64) is installed
  • OR Microsoft Windows XP x64 Edition SP2 is installed
  • OR Microsoft Windows Server 2003 (ia64) SP2 is installed
  • AND Netapi32.dll version is less than 5.2.3790.4392
  • OR Check for vulnerable Windows (x64)/(x86) and Netapi32.dll version
  • Check for vulnerable Windows (x64)/(x86)
  • Microsoft Windows Vista x64 Edition is installed
  • OR Microsoft Windows Vista (32-bit) is installed
  • AND Check for LDR/GDR
  • Check for GDR
  • Netapi32.dll version is less than 6.0.6000.16764
  • OR Check for LDR
  • Netapi32.dll version is greater than 6.0.6000.20000
  • AND Netapi32.dll version is less than 6.0.6000.20937
  • OR Check for vulnerable Windows SP1(X86)/(X64)/Server 2008 (X86)/(X64)/(IA-64) and Netapi32.dll version
  • Check for vulnerable Windows SP1(X86)/(X64)/Server 2008 (X86)/(X64)/(IA-64)
  • Microsoft Windows Vista (32-bit) Service Pack 1 is installed
  • OR Microsoft Windows Server 2008 (32-bit) is installed
  • OR Microsoft Windows Vista x64 Edition Service Pack 1 is installed
  • OR Microsoft Windows Server 2008 (64-bit) is installed
  • OR Microsoft Windows Server 2008 (ia-64) is installed
  • AND Check for LDR/GDR
  • Check for GDR
  • Netapi32.dll version is less than 6.0.6001.18157
  • OR Check for LDR
  • Netapi32.dll version is greater than 6.0.6001.22000
  • AND Netapi32.dll version is less than 6.0.6001.22288
  • BACK