Description: Two vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious people to expose sensitive information and compromise a vulnerable system.
1) A boundary error in the Server service (SRV.SYS) when handling first-class Mailslot messages can be exploited to corrupt memory by sending a specially crafted packet to the service.
Successful exploitation allows execution of arbitrary code.
2) An uninitialised buffer in the Server protocol driver can be exploited to view data from the Server Message Block buffers by sending specially crafted packets to the service.
Provided and/or discovered by: 1) Pedram Amini, TippingPoint Security Research Team working with HD Moore.
2) Mike Price and Rafal Wojtczuk of McAfee Avert Labs (the vendor alsocredits Nicolas Pouvesle, Tenable Network Security).
Changelog: 2006-07-12: Added link to US-CERT vulnerability note. Added additional information from TippingPoint and McAfee.
2006-07-20: Added link to US-CERT vulnerability note.
2006-08-13: Updated link to Windows XP SP1/SP2 patches.
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.