Title: Microsoft Windows WINS Association Context Validation Remote Code Execution
Info
Disclosure
Dec 14, 2004
Discovery
Unknown
Dates
Exploit
Jan 02, 2005
Solution
Unknown
Description
Microsoft Windows Server contains a flaw that may allow a remote attacker to execute arbitrary code. The issue is due to an error in 'WINS.EXE' when handling replication packets. By sending a specially crafted WINS replication packet containing a modified memory pointer, a remote attacker could execute arbitrary code resulting in a loss of integrity.
Microsoft has released a patch to address this vulnerability. It is also possible to correct the flaw by implementing the following workaround: Disable the WINS service.
1. Control Panel -> "Add or Remove Programs"
2. "Components" -> "Networking Services" -> "Details".
3. Clear box next to "Windows Internet Naming Service (WINS)"