Lucene search

K
cveMicrosoftCVE-2006-1314
HistoryJul 11, 2006 - 9:05 p.m.

CVE-2006-1314

2006-07-1121:05:00
microsoft
web.nvd.nist.gov
46
cve-2006-1314
server service
srv.sys
buffer overflow
microsoft windows
remote execution
memory corruption
mailslot messages

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.8

Confidence

Low

EPSS

0.945

Percentile

99.2%

Heap-based buffer overflow in the Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to execute arbitrary code via crafted first-class Mailslot messages that triggers memory corruption and bypasses size restrictions on second-class Mailslot messages.

Affected configurations

Nvd
Node
microsoftwindows_2000sp4fr
OR
microsoftwindows_2003_serverMatch64-bit
OR
microsoftwindows_2003_serverMatchitanium
OR
microsoftwindows_2003_serverMatchr2
OR
microsoftwindows_2003_serverMatchsp1
OR
microsoftwindows_2003_serverMatchsp1itanium
OR
microsoftwindows_xp64-bit
OR
microsoftwindows_xpsp1tablet_pc
OR
microsoftwindows_xpsp2tablet_pc
VendorProductVersionCPE
microsoftwindows_xpcpe:/o:microsoft:windows_xp::sp1::
microsoftwindows_2003_server64-bitcpe:/o:microsoft:windows_2003_server:64-bit:::
microsoftwindows_2003_serveritaniumcpe:/o:microsoft:windows_2003_server:itanium:::
microsoftwindows_2003_serverr2cpe:/o:microsoft:windows_2003_server:r2:::
microsoftwindows_2000cpe:/o:microsoft:windows_2000::sp4::fr
microsoftwindows_xpcpe:/o:microsoft:windows_xp::::
microsoftwindows_2003_serversp1cpe:/o:microsoft:windows_2003_server:sp1:::
microsoftwindows_xpcpe:/o:microsoft:windows_xp::sp2::

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.8

Confidence

Low

EPSS

0.945

Percentile

99.2%