Microsoft Windows DHCP Client Service Remote Buffer Overflow
SecurityAlert : 1201 CVE : CVE-2006-2372 SecurityRisk : High (About) Remote Exploit : Yes Local Exploit : No Exploit Available : No Credit : Mariano Nuñez Di Croce (mnunez cybsec com) Published : 12.07.2006
Affected Software :
Microsoft Windows DHCP Client Service
* Microsoft Windows 2000 (<= SP4)
* Microsoft Windows XP (<= SP2)
* Microsoft Windows 2003 (<= SP1)
Advisory Content :
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
(The following advisory is also available in PDF format for download at:
http://www.cybsec.com/vuln/CYBSEC-Security_Pre-Advisory_Microsoft_Window
s_DHCP_Client_Service_Remote_Buffer_Overflow.pdf )
CYBSEC S.A.
www.cybsec.com
Pre-Advisory Name: Microsoft Windows DHCP Client Service Remote Buffer
Overflow
==================
Reference to Vulnerability Disclosure Policy:
=============================================
http://www.cybsec.com/vulnerability_policy.pdf
Vulnerability Description:
==========================
A remote buffer overflow vulnerability has been identified in Microsoft
Windows DHCP-Client service.
Technical Details:
==================
Technical details will be released 30 days after publication of this
pre-advisory.
This was agreed upon with Microsoft to allow their customers to upgrade
affected software prior to technical knowledge been publicly available.
Impact:
=======
Exploiting this vulnerability, an attacker would be able to execute code
remotely with SYSTEM privileges over DHCP-enabled Microsoft Windows
systems.
Solutions:
==========
Microsoft has released a hotfix to address this vulnerability.
Customers should apply the hotfix immediately or upgrade their systems
through Microsoft Windows Update system.
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.