📄 9432.txt
字号:
Rule--Sid9432--Summary:This event is generated when an attempt is made to exploit a known vulnerability with Microsoft Agent--Impact:Serious. Execution of code is possible.--Detailed Information:Microsoft Agent is vulnerable to a buffer overflow condition that may be exploited by a remote attacker via a response from a web server to an affected host.The problem lies in the processing of malformed HTTP character files (.ACF), the agent incorrectly parses these files and exploitation of a buffer overflow condition may be possible.--Affected Systems:Microsoft, Windows 2000, Service Pack 4Microsoft, Windows XP, Service Pack 2Microsoft, Windows XP, Professional 64-bitMicrosoft, Windows Server 2003Microsoft, Windows Server 2003, Service Pack 1Microsoft, Windows Server 2003, (Itanium)Microsoft, Windows Server 2003, SP1 (Itanium)Microsoft, Windows Server 2003, 64-bit--Attack Scenarios:An attacker would need to supply a malformed .acf file in a response from a web server for the agent to process.--Ease of Attack:Simple. Exploit code exists.--False Positives:None known.--False Negatives:None known.--Corrective Action:Apply the appropriate vendor supplied patches.--Contributors:Sourcefire Vulnerability Research Team--Additional References:--
⌨️ 快捷键说明
复制代码
Ctrl + C
搜索代码
Ctrl + F
全屏模式
F11
切换主题
Ctrl + Shift + D
显示快捷键
?
增大字号
Ctrl + =
减小字号
Ctrl + -