| VID |
26079 |
| Severity |
40 |
| Port |
139,445 |
| Protocol |
TCP |
| Class |
SMB |
| Detailed Description |
The Hotfix(KB837001) for 'Code Execution Vulnerability in Microsoft Jet Database Engine' has not been applied. A buffer Overflow Vulnerability exists in the Microsoft Jet Database Engine (Jet), caused by improper processing a database request. The Microsoft Jet Database Engine (Jet) provides data access to application such as Microsoft Access, Microsoft Visual Basic, IIS Applications and may third party applications. A remote attacker could execute a code on an affected system, by creating s specially crafted database query and sending to it. It could allow an attacker to take complete control of an affected system, including installing program; viewing, changing, or deleting data; or creating new accounts with full privileges.
* Note: This check requires an account with Guest or upper privileges which can access the registry of the remote host to scan. Absence of these condition will result in the check not being performed and a False Negative for all vulnerable hosts.
* References: http://www.microsoft.com/technet/security/bulletin/MS04-014.mspx
* Platforms Affected: Microsoft Windows XP, SP1, 64bit Edition SP1, 64bit Edition Version 2003 Microsoft Windows 2000 SP2, SP3, SP4 Microsoft Windows NT Server 4.0 SP6a, Workstation 4.0 SP6a, TSE SP6 Microsoft Windows Server 2003 64bit Edition |
| Recommendation |
Apply the appropriate patch for your system, as listed in the Microsoft Security Bulletin MS04-014 at http://www.microsoft.com/technet/security/bulletin/MS04-014.mspx
-- OR --
Patches for Windows platforms are also available from the Microsoft Windows Update Web site, http://windowsupdate.microsoft.com . Windows Update detects what version of Windows you are running and offers the appropriate patch. |
| Related URL |
CVE-2004-0197 (CVE) |
| Related URL |
10112 (SecurityFocus) |
| Related URL |
15703 (ISS) |
|