Microsoft Windows RPCSS DCOM Interface DoS
Publish Date: 15 lutego 2011
Severity: : High
CVE Kennungen: : CVE-2003-0605
Advisory Date: 15 lutego 2011
DESCRIPTION
The RPC DCOM interface in Windows 2000 SP3 and SP4 allows remote
attackers to cause a denial of service (crash), and local attackers to use the
DoS to hijack the epmapper pipe to gain privileges, via certain messages to the
__RemoteGetClassObject interface that cause a NULL pointer to be passed to the
PerformScmStage function.
INFORMATION EXPOSURE
Trend Micro Deep Security shields networks through Deep Packet Inspection (DPI) rules. Trend Micro customers using OfficeScan with Intrusion Defense Firewall (IDF) plugin are also protected from attacks using these vulnerabilities. Please refer to the filter number and filter name when applying appropriate DPI and/or IDF rules.
SOLUTION
Trend Micro Deep Security DPI Rule Number: 1001448
Trend Micro Deep Security DPI Rule Name: 1001448 - Microsoft Windows RPCSS DCOM Interface DoS
AFFECTED SOFTWARE AND VERSION:
- Microsoft Windows 2000 Advanced Server
- Microsoft Windows 2000 Advanced Server SP1
- Microsoft Windows 2000 Advanced Server SP2
- Microsoft Windows 2000 Advanced Server SP3
- Microsoft Windows 2000 Advanced Server SP4
- Microsoft Windows 2000 Datacenter Server
- Microsoft Windows 2000 Datacenter Server SP1
- Microsoft Windows 2000 Datacenter Server SP2
- Microsoft Windows 2000 Datacenter Server SP3
- Microsoft Windows 2000 Datacenter Server SP4
- Microsoft Windows 2000 Professional
- Microsoft Windows 2000 Professional SP1
- Microsoft Windows 2000 Professional SP2
- Microsoft Windows 2000 Professional SP3
- Microsoft Windows 2000 Professional SP4
- Microsoft Windows 2000 Server
- Microsoft Windows 2000 Server SP1
- Microsoft Windows 2000 Server SP2
- Microsoft Windows 2000 Server SP3
- Microsoft Windows 2000 Server SP4