Skip to main content

Microsoft Windows LRPC Client Buffer Overrun Vulnerability

Last Update Date: 13 Dec 2013 Release Date: 11 Dec 2013 3732 Views

RISK: Medium Risk

TYPE: Operating Systems - Windows OS

TYPE: Windows OS

An elevation of privilege vulnerability exists in Microsoft Local Remote Procedure Call (LRPC) where an attacker spoofs an LRPC Server and uses a specially crafted LPC port message to cause a stack-based buffer overflow condition on the LRPC client. LRPC internally uses Microsoft Local Procedure Call (LPC). So, in effect, any LPC consumer might be impacted by this vulnerability, if not properly implemented. An attacker who successfully exploited this vulnerability could then install programs; view, change, or delete data; or create new accounts with full administrator rights.


Impact

  • Elevation of Privilege

System / Technologies affected

  • Windows XP
  • Windows Server 2003

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.


Vulnerability Identifier


Source


Related Link