CVE-2009-0568: Critical severity Microsoft Windows Server 2008 vulnerability
The RPC Marshalling Engine (aka NDR) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP2, Vista Gold, SP1, and SP2, and Server 2008 SP2 does not properly maintain its internal state, which allows remote attackers to overwrite arbitrary memory locations via a crafted RPC message that triggers incorrect pointer reading, related to "IDL interfaces containing a non-conformant varying array" and FCSMVARRAY, FCLGVARRAY, FCVARIABLEREPEAT, and FCVARIABLEOFFSET, aka "RPC Marshalling Engine Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0568?
CVE-2009-0568 has a critical severity rating due to the potential for remote code execution.
How do I fix CVE-2009-0568?
To fix CVE-2009-0568, apply the latest security updates and patches provided by Microsoft for affected operating systems.
What systems are affected by CVE-2009-0568?
CVE-2009-0568 affects Microsoft Windows 2000, XP (SP2 and SP3), Server 2003, Vista (all versions), and Server 2008.
What type of attack is associated with CVE-2009-0568?
CVE-2009-0568 can be exploited through crafted RPC messages that manipulate the RPC Marshalling Engine.
Are there any known exploits for CVE-2009-0568?
Yes, there are known exploits for CVE-2009-0568 that allow attackers to overwrite arbitrary memory locations.