This script is Copyright (C) 2009-2015 Tenable Network Security, Inc.
Arbitrary code can be executed on the remote host through the Web
Services for Devices API (WSDAPI).
The remote Windows host is running a vulnerable version of WSDAPI.
Sending the affected service a packet with a specially crafted header
can result in arbitrary code execution. An attacker on the same subnet
could exploit this to take complete control of the system.
See also :
Microsoft has released a set of patches for Windows Vista and 2008.
Risk factor :
High / CVSS Base Score : 8.3
CVSS Temporal Score : 6.5
Public Exploit Available : true
Family: Windows : Microsoft Bulletins
Nessus Plugin ID: 42437 ()
Bugtraq ID: 36919
CVE ID: CVE-2009-2512
The cookie settings on this website are set to 'allow all cookies' to give you the very best website experience. If you continue without changing these settings, you consent to this - but if you want, you can opt out of all cookies by clicking below.