Oval Definition:oval:org.mitre.oval:def:6300
Revision Date:2009-12-28Version:43
Title:License Logging Server Heap Overflow Vulnerability
Description:The License Logging Server (llssrv.exe) in Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrary code via an RPC message containing a string without a null terminator, which triggers a heap-based buffer overflow in the LlsrLicenseRequestW method, aka "License Logging Server Heap Overflow Vulnerability."
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2009-2523
Platform(s):Microsoft Windows 2000
Product(s):SMBv2
Definition Synopsis
  • Microsoft Windows 2000 SP4 or later is installed
  • AND The version of Llssrv.exe is less than 5.0.2195.7337
  • BACK