SMB: Invalid Workstation Service Call

This signature detects attempts to exploit a known vulnerability in the Microsoft Windows Workstation Service. A successful attack can lead to a buffer overflow and arbitrary remote code execution within the context of the service user (typically Administrator).

Extended Description

Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to execute arbitrary code via NetrJoinDomain2 RPC messages with a long hostname.

Affected Products

Microsoft windows_xp

Short Name
SMB:OF:WKSSVC-CALL
Severity
Critical
Recommended
False
Recommended Action
Drop
Category
SMB
Keywords
CVE-2006-4691 Call Invalid Service Workstation bid:20985
Release Date
11/14/2006
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3724
False Positive
Unknown
Vendors

Microsoft

CVSS Score

10.0

Found a potential security threat?