Skip to main content

Microsoft RPC Marshalling Engine Vulnerability ( 10 June 2009 )

Last Update Date: 28 Jan 2011 Release Date: 10 Jun 2009 5118 Views

RISK: Medium Risk

An elevation of privilege vulnerability exists in the Windows remote procedure call (RPC) facility where the RPM Marshalling Engine does not update its internal state appropriately. The failure to update internal state could lead to a pointer being read from an incorrect location. An attacker who successfully exploited this vulnerability could execute arbitrary code and take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.