CVE Database
/

CVE-2008-4114

Back to search

CVE-2008-4114

Published: Sep 16, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via an SMB WRITE_ANDX packet with an offset that is inconsistent with the packet size, related to "insufficiently validating the buffer size," as demonstrated by a request to the \PIPE\lsarpc named pipe, aka "SMB Validation Denial of Service Vulnerability."

VendorProductVersions

n/a

n/a

affected
n/a

References

oval:org.mitre.oval:def:6044
vdb-entry
signature
x_refsource_OVAL
6463
exploit
x_refsource_EXPLOIT-DB
31179
vdb-entry
x_refsource_BID
MS09-001
vendor-advisory
x_refsource_MS
31883
third-party-advisory
x_refsource_SECUNIA
ADV-2008-2583
vdb-entry
x_refsource_VUPEN
TA09-013A
third-party-advisory
x_refsource_CERT
win-writeandx-dos(45146)
vdb-entry
x_refsource_XF
1020887
vdb-entry
x_refsource_SECTRACK
oval:org.mitre.oval:def:5262
vdb-entry
signature
x_refsource_OVAL

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now