HIGH · 7.5

CVE-2006-0034

Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 a...

Vulnerability Description

Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 allows remote attackers to execute arbitrary code via a long fifth argument to the BuildContextW or BuildContext opcode, which triggers a bug in the NdrAllocate function, aka the MSDTC Invalid Memory Access Vulnerability.

CVSS Score

7.5

HIGH

AV:N/AC:L/Au:N/C:P/I:P/A:P
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
PARTIAL

Affected Products

VendorProductVersions
MicrosoftDistributed Transaction CoordinatorAll versions
MicrosoftWindows 2000All versions
MicrosoftWindows 2003 Serverenterprise
MicrosoftWindows Nt4.0
MicrosoftWindows XpAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2006-0034?

CVE-2006-0034 is a vulnerability with a CVSS score of 7.5 (HIGH). Heap-based buffer overflow in the CRpcIoManagerServer::BuildContext function in msdtcprx.dll for Microsoft Distributed Transaction Coordinator (MSDTC) for Windows NT 4.0 and Windows 2000 SP2 and SP3 a...

How severe is CVE-2006-0034?

CVE-2006-0034 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2006-0034?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Distributed Transaction Coordinator, Microsoft Windows 2000, Microsoft Windows 2003 Server, Microsoft Windows Nt, Microsoft Windows Xp.