Content

(MS09-064) Vulnerability in License Logging Server Could Allow Remote Code Execution (974783)

Type
Logic error
Impact of exploitation
Remote Code Execution
User Interaction
no user interaction is needed
Attack Vector
Malicious local network traffic
Rating
Medium
CVE reference
CVE-2009-2523,
Vendor Status
Responded and patched
Vulnerable systems
Windows  2000 SP4,
Summary
A remote code execution vulnerability exists in Microsoft License Logging Server.

Tab Navigation

Description

Exploitation of the vulnerability doesn't require authentication, which allows an attacker to exploit it by sending a specially crafted network message to a computer running the License Logging service. Successfully exploitation of this vulnerability could allow an attacker to take complete control of the system.

McAfee Product Mitigation & Recommendations

Recommendations

The Vendor has released patches to address this issue http://www.microsoft.com/technet/security/bulletin/ms09-064.mspx

McAfee Product Mitigation

McAfee Foundstone
Signature:
(MS09-064) Vulnerability in License Logging Server Could Allow Remote Code Execution (974783)
Signature identifier:
7314
Release date:
11/10/2009

Additional Resources

(MS09-064) Vulnerability in License Logging Server Could Allow Remote Code Execution (974783)

http://www.microsoft.com/technet/security/bulletin/ms09-064.mspx

All Information

Timeline -

11/10/2009

Vendor has provided a patch.

Description -

Exploitation of the vulnerability doesn't require authentication, which allows an attacker to exploit it by sending a specially crafted network message to a computer running the License Logging service. Successfully exploitation of this vulnerability could allow an attacker to take complete control of the system.

McAfee Product Mitigation & Recommendations

Recommendations -

The Vendor has released patches to address this issue http://www.microsoft.com/technet/security/bulletin/ms09-064.mspx

McAfee Product Mitigation

McAfee Foundstone
Signature:
(MS09-064) Vulnerability in License Logging Server Could Allow Remote Code Execution (974783)
Signature identifier:
7314
Release date:
11/10/2009

Additional Resources

Additional Resources -

(MS09-064) Vulnerability in License Logging Server Could Allow Remote Code Execution (974783)

http://www.microsoft.com/technet/security/bulletin/ms09-064.mspx