First published: Thu Jun 16 2011(Updated: )
The Distributed File System (DFS) implementation in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 does not properly validate fields in DFS responses, which allows remote DFS servers to execute arbitrary code via a crafted response, aka "DFS Memory Corruption Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp3 | |
Microsoft Windows Server | =sp2 | |
Microsoft Windows Server 2003 | =sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-1868 has a critical severity rating due to its potential for remote code execution.
To address CVE-2011-1868, apply the latest security patches provided by Microsoft for affected versions.
CVE-2011-1868 affects Windows XP SP2, Windows XP SP3, and Windows Server 2003 SP2.
Yes, CVE-2011-1868 can be exploited remotely when a malicious DFS server sends a crafted response.
Exploitation of CVE-2011-1868 can lead to arbitrary code execution, allowing attackers to gain control of the affected system.