Reported January 22, 2003, by Microsoft.
· Windows XP
· Windows 2000
· Windows NT 4.0
· Windows NT Server 4.0, Terminal Server Edition (WTS)
The Microsoft Locator Service contains a vulnerability that stems from an unchecked buffer. By sending a specially malformed request to the Locator service, an attacker can cause the Locator service to fail or to run code of the attacker's choice on the system.
To address this vulnerability, Microsoft has released Security Bulletin MS03-001, "Unchecked Buffer in Locater Service Could Lead To Code Execution (810833)," and recommends that affected users immediately apply the appropriate patch mentioned in the bulletin.
Discovered by David Litchfield.