MS-RPC: DCE-RPC Windows Workstation Service Remote Buffer Overflow
This signature detects attempts to exploit a known vulnerability against Windows Workstation Service. A successful attack can lead to arbitrary code execution.
Extended Description
It has been reported that Microsoft Windows Workstation (WKSSVC.DLL) service is prone to a vulnerability that may allow a remote attacker to gain unauthorized access to a vulnerable host. The problem is in the handling of requests by the Workstation Service. The Workstation Service does not properly check bounds on remote data therefore making it possible to overwrite sensitive regions of system memory.
Affected Products
Cisco sn_5420_storage_router,Cisco call_manager
srx-branch-12.3
srx-19.3
srx-branch-19.3
vsrx3bsd-19.2
srx-branch-19.4
vsrx-19.4
mx-12.3
mx-19.4
vmx-19.4
mx-19.3
vsrx3bsd-19.4
srx-19.4
vsrx-12.3
vmx-19.3
vsrx-19.2
srx-12.3
Cisco
Microsoft
9.3
9.0
10.0