MS-RPC: DCE-RPC Remote "atsvc" Bind

This signature detects remote attempts to bind to the "atsvc" service, which provides the ability to remotely schedule process execution. Worms and other malicious programs can use this service to execute programs remotely. However, network administrators can also use this service legitimately inside a secured network to assist with remote administration.

Extended Description

A vulnerability exists in the Windows Task Scheduler's Mstask.exe process. This vulnerability allows an attacker to cause a denial of service.

Short Name
MS-RPC:ATSVC-BIND
Severity
Minor
Recommended
False
Recommended Action
None
Category
MS-RPC
Keywords
"atsvc" Bind DCE-RPC Remote
Release Date
07/12/2004
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3324
False Positive
Unknown

Found a potential security threat?