Get a Pentest and security assessment of your IT network.

Advisories

Microsoft Windows License Logging Service Heap Corruption

A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows. Authentication is not required on certain configurations to exploit this vulnerability. The specific flaw exists in the handling of RPC calls to the License Logging Service (llssrv.exe). When processing arguments to the LlsrLicenseRequestW method a character array is expected to contain a terminating null byte. By supplying data that does not end in a null it is possible to overlap a call to lstrcatW, resulting in a heap overflow. Successful exploitation of this vulnerability can lead to remote system compromise under the credentials of the SYSTEM account.

 

You can download this advisory from the following link: https://packetstormsecurity.com/files/download/82666/TPTI-09-07.txt

Source: https://packetstormsecurity.com/files/82666/Microsoft-Windows-License-Logging-Service-Heap-Corruption.html

Related posts
Advisories

crossZone.txt

Advisories

Secunia Security Advisory 16900

Advisories

Secunia Security Advisory 19793

Advisories

Secunia Security Advisory 22534