Reported January 22, 2003, by Microsoft.

 

 

VERSIONS AFFECTED

 

·         Windows XP

·         Windows 2000

·         Windows NT 4.0

·         Windows NT Server 4.0, Terminal Server Edition (WTS)

 

 

DESCRIPTION

 

The Microsoft Locator Service contains a vulnerability that stems from an unchecked buffer. By sending a specially malformed request to the Locator service, an attacker can cause the Locator service to fail or to run code of the attacker's choice on the system.

 

VENDOR RESPONSE

To address this vulnerability, Microsoft has released Security Bulletin MS03-001, "Unchecked Buffer in Locater Service Could Lead To Code Execution (810833)," and recommends that affected users immediately apply the appropriate patch mentioned in the bulletin.

 

CREDIT          

Discovered by David Litchfield.