>> Microsoft Windows Remote Installation Service Command Execution Vulnerability (MS06-077)
Title : Microsoft Windows Remote Installation Service Command Execution Vulnerability (MS06-077) VUPEN ID : VUPEN/ADV-2006-4970 CVE ID : CVE-2006-5584
Rated as : Moderate Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-12-12
Technical Description
A vulnerability has been identified in Microsoft Windows, which could be exploited by remote attackers to take complete control of an affected system. This flaw is due to an error within the Remote Installation Service (RIS) that enables a TFTP service on the server, which could be exploited by anonymous attackers to overwrite existing operating system files or upload malicious files.
Note : The Remote Install Service is not installed by default.