First published: Wed Dec 13 2006(Updated: )
The Remote Installation Service (RIS) in Microsoft Windows 2000 SP4 uses a TFTP server that allows anonymous access, which allows remote attackers to upload and overwrite arbitrary files to gain privileges on systems that use RIS.
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 2000 | =sp4 | |
=sp4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-5584 is considered a high severity vulnerability due to the potential for remote attackers to gain system privileges.
To fix CVE-2006-5584, it is recommended to disable the Remote Installation Service or restrict access to the TFTP server.
CVE-2006-5584 specifically affects Microsoft Windows 2000 SP4 installations using the Remote Installation Service.
The risks associated with CVE-2006-5584 include unauthorized file uploads and potential system compromise by remote attackers.
An attacker can exploit CVE-2006-5584 by utilizing anonymous access to the TFTP server to upload malicious files.