Windows 2000 Remote Access Service Phonebook Vulnerability Patch

Software Screenshot:
Windows 2000 Remote Access Service Phonebook Vulnerability Patch
Software Details:
Version: MS02-029
Upload Date: 29 Oct 15
Developer: Microsoft
Distribution Type: Freeware
Downloads: 62
Size: 1019 Kb

Rating: 3.0/5 (Total Votes: 1)

The Remote Access Service (RAS) provides dial-up connections between computers and networks over phone lines. RAS is delivered as a native system service in Windows NT 4.0, Windows 2000 and Windows XP, and also is included in a separately downloadable Routing and Remote Access Server (RRAS) for Windows NT 4.0. All of these implementations include a RAS phonebook, which is used to store information about telephone numbers, security, and network settings used to dial-up remote systems.

A flaw exists in the RAS phonebook implementation: a phonebook value is not properly checked, and is susceptible to a buffer overrun. The overrun could be exploited for either of two purposes: causing a system failure, or running code on the system with LocalSystem privileges. If an attacker were able to log onto an affected server and modify a phonebook entry using specially malformed data, then made a connection using the modified phonebook entry, the specially malformed data could be run as code by the system.

Requirements:

Windows 2000

Supported Operation Systems

Similar Software

KeyPass
KeyPass

5 May 15

USBLock
USBLock

24 Oct 15

PennCryptSuite
PennCryptSuite

28 Oct 15

Other Software of Developer Microsoft

Comments to Windows 2000 Remote Access Service Phonebook Vulnerability Patch

Comments not found
Add Comment
Turn on images!