Get a Pentest and security assessment of your IT network.

Advisories

eEye.ASN1-2.txt

eEye Security Advisory – eEye Digital Security has discovered a second critical vulnerability in Microsoft’s ASN.1 library (MSASN1.DLL) that allows an attacker to overwrite heap memory with data he or she controls and cause the execution of arbitrary code. ASN.1 is an industry standard used in a variety of binary protocols, and as a result, this flaw in Microsoft’s implementation can be reached through a number of Windows applications and services. Ironically, the security-related functionality in Windows is especially adept at rendering a machine vulnerable to this attack, including Kerberos (UDP/88) and NTLMv2 authentication (TCP/135, 139, 445).

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/32663/eEye.ASN1-2.txt

Source: https://packetstormsecurity.com/files/32663/eEye.ASN1-2.txt.html

Related posts
Advisories

spoofVulnMSIE.txt

Advisories

sybariAntigen.txt

Advisories

Secunia Security Advisory 19799

Advisories

Secunia Security Advisory 22568