[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
[Full-Disclosure] Windows Lsasrv.dll RPC buffer overflow Remote Exploit (MS04-011)
- To: full-disclosure@xxxxxxxxxxxxxxxx
- Subject: [Full-Disclosure] Windows Lsasrv.dll RPC buffer overflow Remote Exploit (MS04-011)
- From: Paul Tinsley <jackhammer@xxxxxxxxx>
- Date: Mon, 26 Apr 2004 16:18:28 -0500
I haven't seen much discussion about this one other than here:
http://www.incidents.org/diary.php?date=2004-04-25&isc=24f2410ad7a5b786b009d9226c908b92
and I just figured I would pass along that this one is real and does
work. We setup some vmware sessions awhile ago and tested it against
a W2K SP4 box with no success, but a W2K SP4 box with all patches
except MS04-011 and MS04-012 was a successful target. So patching is
probably a good idea if you haven't already done so.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html