MS10-025: Vulnerability in Microsoft Windows Media Services Could Allow Remote Code Execution (980858) (uncredentialed check)

high Nessus Plugin ID 46017

Synopsis

The remote media service is affected by a remote code execution vulnerability.

Description

The version of Windows Media Services running on the remote host is affected by a stack-based buffer overflow condition in the Unicast Service component due to improper sanitization of user-supplied input.
An unauthenticated, remote attacker can exploit this, via specially crafted transport information packets, to execute arbitrary code.

Note that Windows Media Services is not enabled by default on Windows 2000 Server. For the server to be vulnerable, it would have to be configured as a streaming media server by adding the Windows Media Services component in the Windows Components Wizard.

Solution

Microsoft has released a set of patches for Windows 2000.

See Also

https://docs.microsoft.com/en-us/security-updates/SecurityBulletins/2010/ms10-025

Plugin Details

Severity: High

ID: 46017

File Name: smb_kb_980858.nasl

Version: 1.22

Type: remote

Agent: windows

Family: Windows

Published: 4/27/2010

Updated: 11/15/2018

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: High

Base Score: 9.3

Temporal Score: 7.7

Vector: CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C

CVSS v3

Risk Factor: High

Base Score: 8.1

Temporal Score: 7.5

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:microsoft:windows_2000

Required KB Items: ms-streaming/1755/version

Excluded KB Items: Host/not_windows

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/13/2010

Vulnerability Publication Date: 4/13/2010

Exploitable With

CANVAS (CANVAS)

Core Impact

Metasploit (Windows Media Services ConnectFunnel Stack Buffer Overflow)

Reference Information

CVE: CVE-2010-0478

BID: 39356

MSFT: MS10-025

MSKB: 980858