CVE-2007-3039
Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Windows 2000 Professional SP4, and Windows XP SP2 allows attackers to execute arbitrary code via a long string in an opnum 0x06 RPC call to…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 69.1%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Windows 2000 Professional SP4, and Windows XP SP2 allows attackers to execute arbitrary code via a long string in an opnum 0x06 RPC call to port 2103. NOTE: this is remotely exploitable on Windows 2000 Server.
- CVSS 2.0
- 9.0 HIGHAV:N/AC:L/Au:S/C:C/I:C/A:C
- EPSS
- 69.06% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- microsoft/message queuing
- Source
- secure@microsoft.com
References
- http://secunia.com/advisories/28011Vendor Advisory
- http://secunia.com/advisories/28051Vendor Advisory
- http://www.securityfocus.com/archive/1/484891/100/0/threaded
- http://www.securityfocus.com/archive/1/485268/100/0/threaded
- http://www.securityfocus.com/bid/26797
- http://www.securitytracker.com/id?1019077
- http://www.us-cert.gov/cas/techalerts/TA07-345A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/4181
- http://www.zerodayinitiative.com/advisories/ZDI-07-076.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-065
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4474
- https://www.exploit-db.com/exploits/4745
- https://www.exploit-db.com/exploits/4760
- https://www.exploit-db.com/exploits/4934
- http://secunia.com/advisories/28011Vendor Advisory
- http://secunia.com/advisories/28051Vendor Advisory
- http://www.securityfocus.com/archive/1/484891/100/0/threaded
- http://www.securityfocus.com/archive/1/485268/100/0/threaded
- http://www.securityfocus.com/bid/26797
- http://www.securitytracker.com/id?1019077
- http://www.us-cert.gov/cas/techalerts/TA07-345A.htmlUS Government Resource
- http://www.vupen.com/english/advisories/2007/4181
- http://www.zerodayinitiative.com/advisories/ZDI-07-076.html
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2007/ms07-065
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A4474
- https://www.exploit-db.com/exploits/4745
- https://www.exploit-db.com/exploits/4760
- https://www.exploit-db.com/exploits/4934
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.