Denial of Service Condition in Microsoft Windows NT 4.0 Endpoint Mapper Service

A vulnerability exists in NT 4.0 remote procedure call (RPC) endpoint mapper service that an attacker can use to cause a Denial of Service (DoS) condition.

Ken Pfeil

September 12, 2001

1 Min Read
ITPro Today logo

Reported September 10, 2001, byMicrosoft.

VERSIONS AFFECTED

  • Microsoft Windows NT 4.0 Workstation

  • Microsoft Windows NT 4.0 Server

  • Microsoft Windows NT 4.0 Server, Enterprise Edition

  • Microsoft Windows NT Server 4.0, Terminal Server Edition

 

DESCRIPTION
Avulnerability exists in NT 4.0 remote procedure call (RPC) endpoint mapperservice that an attacker can use to cause a Denial of Service (DoS) condition. Aproblem in the service causes it to fail when an attacker sends a request thatcontains a particular type of malformed data.

 

VENDOR RESPONSE

Thevendor, Microsoft, has released securitybulletin MS01-048to address this vulnerability and recommends that affected users apply the patchprovided at its Web site. Microsoft will provide a patch for WTS at bulletin MS01-048when the patch becomes available.

 

CREDIT
Discoveredby SeiichiTatsukawa of Rational Software.

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like