Vulnerability Name: | CCN-13171 | ||||||
Published: | 2003-09-11 | ||||||
Updated: | 2003-09-11 | ||||||
Summary: | Multiple editions of Microsoft Windows Server 2003 are vulnerable to stack-based buffer overflows. A remote attacker can cause a stack-based buffer overflow without overwriting the canary or cookie placed on the stack to detect stack-based buffer overflows. This allows the attacker to bypass the security mechanism used for the detection and protection of stack-based buffer overflow | ||||||
CVSS v3 Severity: | 7.3 High (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L)
| ||||||
CVSS v2 Severity: | 7.5 High (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P)
| ||||||
Vulnerability Consequences: | Gain Access | ||||||
References: | Source: CCN Type: BugTraq Mailing List, Thu Sep 11 2003 - 09:40:20 CDT Windows 2003 Server - Defeating the stack protection mechanism Source: CCN Type: NGSSoftware Paper: defeating-w2k3-stack-protection Defeating the Stack Based Buffer Overflow Prevention Mechanism of Microsoft Windows 2003 Server. Source: CCN Type: BID-8522 Multiple Microsoft Windows 2003 Stack Protection Implementation Weaknesses Source: XF Type: UNKNOWN winserver2003-bypass-security-bo(13171) | ||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||
BACK |