Vulnerability Name: | CVE-2000-1089 (CCN-5623) | ||||||||
Assigned: | 2000-12-04 | ||||||||
Published: | 2000-12-04 | ||||||||
Updated: | 2018-10-12 | ||||||||
Summary: | Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Service Buffer Overflow" vulnerability. | ||||||||
CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Privileges | ||||||||
References: | Source: MITRE Type: CNA CVE-2000-1089 Source: CCN Type: Danware Web site Vulnerability Report For Microsoft PhoneBook Server overflow Source: CCN Type: Microsoft Security Bulletin MS00-094 FAQ Microsoft Security Bulletin (MS00-94):Frequently Asked Questions Source: CCN Type: Microsoft Security Bulletin MS00-094 Patch Available for "Phone Book Service Buffer Overflow" Vulnerability Source: CCN Type: Microsoft Security Bulletin MS01-033 Unchecked Buffer in Index Server ISAPI Extension Could Enable Web Server Compromise Source: CCN Type: Microsoft Security Bulletin MS01-041 Malformed RPC Request Can Cause Service Failure Source: CCN Type: Microsoft Security Bulletin MS01-044 15 August 2001 Cumulative Patch for IIS Source: CCN Type: Microsoft Security Bulletin MS02-001 Trusting Domains Do Not Verify Domain Membership of SIDs in Authorization Data Source: CCN Type: Microsoft Security Bulletin MS02-018 Cumulative Patch for Internet Information Services (Q319733) Source: CCN Type: Microsoft Security Bulletin MS03-018 Cumulative Patch for Internet Information Service (811114) Source: CCN Type: OSVDB ID: 463 Microsoft IIS Phone Book Service /pbserver/pbserver.dll Remote Overflow Source: BID Type: Exploit, Patch, Vendor Advisory 2048 Source: CCN Type: BID-2048 Microsoft PhoneBook Server Buffer Overflow Source: ATSTAKE Type: Exploit, Patch, Vendor Advisory A120400-1 Source: CCN Type: @stake, Inc. Security Advisory A120400-1 IIS 4.0/5.0 Phone Book server buffer overrun Source: MS Type: UNKNOWN MS00-094 Source: XF Type: UNKNOWN phone-book-service-bo(5623) Source: XF Type: UNKNOWN phone-book-service-bo(5623) Source: CCN Type: Rapid7 Vulnerability & Exploit Database Cisco Device HTTP Device Manager Access | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||
BACK |