First published: Tue Jun 13 2006(Updated: )
Buffer overflow in the Routing and Remote Access service (RRAS) in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," aka the "RRAS Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 2003 Server | =enterprise_edition_64-bit-sp1 | |
Microsoft Windows 2003 Server | =datacenter_edition_64-bit-sp1 | |
Microsoft Windows 2003 Server | =standard | |
Microsoft Windows XP | =sp1 | |
Microsoft Windows 2003 Server | =web | |
Microsoft Windows 2003 Server | =datacenter_edition_64-bit | |
Microsoft Windows 2003 Server | =enterprise_64-bit | |
Microsoft Windows XP | =gold | |
Microsoft Windows 2000 | ||
Microsoft Windows XP | ||
Microsoft Windows 2003 Server | =standard_64-bit | |
Microsoft Windows 2000 | =sp4 | |
Microsoft Windows 2003 Server | =enterprise_edition_64-bit | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | ||
Microsoft Windows XP | =sp1 | |
Microsoft Windows 2000 | =sp2 | |
Microsoft Windows 2003 Server | =r2 | |
Microsoft Windows 2003 Server | =web-sp1 | |
Microsoft Windows 2000 | =sp1 | |
Microsoft Windows 2003 Server | =sp1 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | ||
Microsoft Windows 2003 Server | =enterprise_edition-sp1 | |
Microsoft Windows 2003 Server | =standard-sp1 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows 2003 Server | =datacenter_edition | |
Microsoft Windows 2003 Server | =datacenter_edition-sp1 | |
Microsoft Windows 2000 | =sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-2370 has a critical severity rating due to its potential for remote code execution.
To fix CVE-2006-2370, you should apply the latest security patches provided by Microsoft for affected versions.
CVE-2006-2370 affects Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Windows Server 2003 SP1 and earlier.
Yes, CVE-2006-2370 can be exploited by remote unauthenticated or authenticated attackers.
CVE-2006-2370 is associated with buffer overflow attacks through crafted RPC requests.