CVE-2008-3466
15.10.2008, 00:12
Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, which allows remote attackers to bypass authentication and execute arbitrary programs via a crafted SNA RPC message using opcode 1 or 6 to call the CreateProcess function, aka "HIS Command Execution Vulnerability."Enginsight
Vendor | Product | Version |
---|---|---|
microsoft | host_integration_server_2000 | * |
microsoft | host_integration_server_2000 | * |
microsoft | host_integration_server_2004 | * |
microsoft | host_integration_server_2004 | * |
microsoft | host_integration_server_2004 | * |
microsoft | host_integration_server_2006 | * |
microsoft | host_integration_server_2006 | * |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
References