CVE-2009-1924: Integer Overflow
Integer overflow in the Windows Internet Name Service (WINS) component for Microsoft Windows 2000 SP4 allows remote WINS replication partners to execute arbitrary code via crafted data structures in a packet, aka "WINS Integer Overflow Vulnerability."
Affected Software
Event History
Frequently Asked Questions
Which systems are exposed to this issue?
The affected software listed is Microsoft Windows 2000 and Microsoft Windows 2003 Server. The vulnerable component is WINS, so exposure is relevant to systems using that service.
What does an attacker need to exploit it?
An attacker must be a remote WINS replication partner and send a packet containing crafted data structures. No authentication is required according to the supplied attack vector.
What is the potential impact of successful exploitation?
Successful exploitation can allow arbitrary code execution. The listed impact includes complete compromise of confidentiality, integrity, and availability.