| VID |
26114 |
| Severity |
40 |
| Port |
139,445 |
| Protocol |
TCP |
| Class |
SMB |
| Detailed Description |
The Hotfix(KB888302) for the 'Information Disclosure Vulnerability in Windows' seems not to have been applied. Microsoft Windows XP SP1 and SP2 could allow a remote attacker to obtain sensitive information over the use of a named pipe through a NULL session. An attacker who successfully exploited this vulnerability could remotely read the user names for users who have an open connection to an available shared resource.
* References: http://www.microsoft.com/technet/security/bulletin/ms05-007.mspx http://www.kb.cert.org/vuls/id/939074 http://www.securityfocus.com/archive/1/389935
* Platforms Affected: Microsoft Windows XP Any version SP2 Microsoft Windows XP 64-bit Edition SP1 |
| Recommendation |
Apply the appropriate patch (KB888302) for your system, as listed in Microsoft Security Bulletin MS05-007 at http://www.microsoft.com/technet/security/bulletin/ms05-007.mspx
-- OR --
Patches for Windows platforms are also available from the Microsoft Windows Update Web site, http://windowsupdate.microsoft.com . Windows Update detects what version of Windows you are running and offers the appropriate patch. |
| Related URL |
CVE-2004-0848 (CVE) |
| Related URL |
12480 (SecurityFocus) |
| Related URL |
19107,19112 (ISS) |
|