xfocus logo xfocus title
首页 焦点原创 安全文摘 安全工具 安全漏洞 焦点项目 焦点论坛 关于我们
添加工具Xcon English Version

HOD-ms05039-pnp-expl.c


提交时间:2005-08-13
提交用户:eyas
工具分类:攻击程序
运行平台:Windows
工具大小:14698 Bytes
文件MD5 :5ee6236ad33b7a55a5d9326fb48bac63
工具来源:bugtraq

/* HOD-ms05039-pnp-expl.c: 2005-08-10: PUBLIC v.0.2

(MS05-039) Microsoft Windows Plug-and-Play Service Remote Overflow (Universal Exploit + no crash shellcode)

exploit attached.

Description:
A remote code execution and local elevation of privilege
vulnerability exists in Plug and Play that could allow an
attacker who successfully exploited this vulnerability to take
complete control of the affected system.

This is a remote code execution and local privilege elevation
vulnerability. On Windows 2000, an anonymous attacker could
remotely try to exploit this vulnerability.

On Windows XP Service Pack 1, only an authenticated user could
remotely try to exploit this vulnerability.
On Window XP Service Pack 2 and Windows Server 2003, only an
administrator can remotely access the affected component.
Therefore, on Windows XP Service Pack 2 and Windows Server 2003,
this is strictly a local privilege elevation vulnerability.
An anonymous user cannot remotely attempt to exploit this
vulnerability on Windows XP Service Pack 2 and Windows
Server 2003.

Solution:
    http://www.microsoft.com/technet/security/Bulletin/MS05-039.mspx

>> 下载 <<