SMB: Microsoft Windows Print Spooler service Buffer Overflow

This signature detects attempts to exploit a known vulnerability in the Microsoft Print Spooler service. A successful attack can lead to remote code execution.

Extended Description

Buffer overflow in the Print Spooler service (Spoolsv.exe) for Microsoft Windows 2000, Windows XP, and Windows Server 2003 allows remote attackers to execute arbitrary code via a malicious message.

Affected Products

Microsoft windows_2000

References

CVE: CVE-2005-1984

Short Name
SMB:MS-WIN-PRINT-SPOOLER-BO
Severity
Major
Recommended
False
Recommended Action
Drop
Category
SMB
Keywords
Buffer CVE-2005-1984 Microsoft Overflow Print Spooler Windows service
Release Date
10/18/2016
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3761
False Positive
Unknown
Vendors

Microsoft

CVSS Score

7.5

Found a potential security threat?