Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2009-0086

Overview

Vulnerability Score 10.0 10.0
CVE Id CVE-2009-0086
Last Modified 21 Aug 2010 01:29:42
Published 15 Apr 2009 04:00:00
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector NETWORK
Access Complexity LOW
Authentication NONE

CVE-2009-0086

Summary

Integer underflow in Windows HTTP Services (aka WinHTTP) in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote HTTP servers to execute arbitrary code via crafted parameter values in a response, related to error handling, aka "Windows HTTP Services Integer Underflow Vulnerability."

Vulnerable Systems

Operating System

  • Microsoft Windows 2000

  • Microsoft Windows Server 2003

  • Microsoft Windows Server 2008

  • Microsoft Windows Vista

  • Microsoft Windows Vista Gold

  • Microsoft Windows Xp


References

CERT - TA09-104A

MS - MS09-013

VUPEN - ADV-2009-1027

SECTRACK - 1022041

BID - 34435

SECUNIA - 34677

OSVDB - 53620


Last Updated: 27 May 2016 10:50:06