The Remote Installation Service (RIS) in Microsoft Windows 2000 SP4 uses a TFTP server that allows anonymous access, which allows remote attackers to upload and overwrite arbitrary files to gain privileges on systems that use RIS.
References
Configurations
History
21 Nov 2024, 00:19
Type | Values Removed | Values Added |
---|---|---|
References | () http://secunia.com/advisories/23312 - | |
References | () http://securitytracker.com/id?1017368 - | |
References | () http://www.kb.cert.org/vuls/id/238064 - US Government Resource | |
References | () http://www.securityfocus.com/archive/1/454969/100/200/threaded - | |
References | () http://www.securityfocus.com/bid/21495 - | |
References | () http://www.us-cert.gov/cas/techalerts/TA06-346A.html - US Government Resource | |
References | () http://www.vupen.com/english/advisories/2006/4970 - | |
References | () https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-077 - | |
References | () https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A375 - |
Information
Published : 2006-12-13 01:28
Updated : 2024-11-21 00:19
NVD link : CVE-2006-5584
Mitre link : CVE-2006-5584
CVE.ORG link : CVE-2006-5584
JSON object : View
Products Affected
microsoft
- windows_2000
CWE