Skip to main content

Microsoft Windows Pragmatic General Multicast (PGM) Multiple Vulnerabilities( 11 June 2008 )

Last Update Date: 28 Jan 2011 Release Date: 11 Jun 2008 5331 Views

RISK: Medium Risk

1. PGM Invalid Length Vulnerability

A denial of service vulnerability exists in implementations of the Pragmatic General Multicast (PGM) protocol on Microsoft Windows XP and Windows Server 2003. The vulnerability is due to improper validation of specially crafted PGM packets. An attacker who successfully exploited this vulnerability could cause the computer to become non-responsive and require a restart to restore functionality.

2. PGM Malformed Fragment Vulnerability

A denial of service vulnerability exists in implementations of the Pragmatic General Multicast (PGM) protocol on Microsoft Windows XP, Windows Server 2003, Windows Vista, and Windows Server 2008. The protocol's parsing code does not properly validate specially crafted PGM fragments and will cause the affected system to become non-responsive until the attack has ceased.