>> Microsoft Windows Winsock Hostname and DNS Client Vulnerabilities (MS06-041)
Title : Microsoft Windows Winsock Hostname and DNS Client Vulnerabilities (MS06-041) VUPEN ID : VUPEN/ADV-2006-3211 CVE ID : CVE-2006-3440 - CVE-2006-3441
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-08-08
Technical Description
Two vulnerabilities have been identified in Microsoft Windows, which could be exploited by remote attackers to take complete control of an affected system.
The first issue is due to a buffer overflow error in the Winsock API when handling malformed messages, which could be exploited by remote attackers to execute arbitrary commands by convincing a user to open a specially crafted file or visit a malicious web site.
The second vulnerability is due to a buffer overflow error in the DNS client layer when handling malformed DNS related communications, which could be exploited by remote attackers to execute arbitrary commands by sending malformed packets to a vulnerable system.