MS-RPC: SPOOLSS Buffer Overflow (1)

This signature detects attempts to exploit a known vulnerability against Microsoft Windows SPOOLSS service. Because of improper bounds checking in the Print Spooler service, an attacker can trigger a buffer overflow in the affected system. This action can lead to arbitrary code execution at System level privileges.

Extended Description

Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.

Affected Products

Microsoft windows_2000

Short Name
MS-RPC:OF:SPOOLSS-1
Severity
Critical
Recommended
False
Recommended Action
None
Category
MS-RPC
Keywords
(1) Buffer CVE-2005-1984 Overflow SPOOLSS bid:14514
Release Date
11/14/2005
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Frequently
Vendors

Microsoft

CVSS Score

7.5

Found a potential security threat?