HTTP: WebDav Mini-Redirector Remote Code Execution

This signature detects attempts to exploit a known vulnerability against WebDav Mini-Redirector. A successful attack can allow attackers to execute remote code on the target system.

Extended Description

Microsoft Windows is prone to a heap-overflow vulnerability in the WebDAV Mini-Redirector component (also known as the Web Client service). This vulnerability may be triggered by a malicious WebDAV response. A successful exploit could let a remote attacker execute arbitrary code with SYSTEM privileges, completely compromising an affected computer. To be affected, the Web Client service must be enabled on the computer. The Web Client service is disabled by default on Microsoft Windows Server 2003.

Affected Products

Nortel_networks self-service_speech_server,Microsoft windows_xp_professional

References

BugTraq: 27670

CVE: CVE-2008-0080

Short Name
HTTP:STC:DAVREDIR
Severity
Critical
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2008-0080 Code Execution Mini-Redirector Remote WebDav bid:27670
Release Date
02/12/2008
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

srx-branch-12.3

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx-12.3

vmx-19.3

srx-12.3

Sigpack Version
3764
False Positive
Unknown
Vendors

Nortel_networks

Microsoft

CVSS Score

10.0

Found a potential security threat?