MS04-045: WINS Code Execution (870763)
Critical Nessus Plugin ID 15962
SynopsisArbitrary code can be executed on the remote host via the WINS service.
DescriptionThe remote Windows Internet Naming Service (WINS) server is prone to a heap overflow attack that could allow an attacker to execute arbitrary code on this host.
To exploit this flaw, an attacker would need to send a specially crafted packet to port 42 of the remote host.
SolutionMicrosoft has released a set of patches for Windows NT, 2000 and 2003.