>> Microsoft Windows Message Queuing Service Code Execution (MS07-065)
Title : Microsoft Windows Message Queuing Service Code Execution (MS07-065) VUPEN ID : VUPEN/ADV-2007-4181 CVE ID : CVE-2007-3039
Rated as : High Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2007-12-11
Technical Description
A vulnerability has been identified in Microsoft Windows, which could be exploited by attackers to cause a denial of service or take complete control of an affected system. This issue is caused by a buiffer overflow error in the Message Queuing Service when processing user-supplied strings, which could be exploited by remote unauthenticated attackers to crash or compromise a vulnerable Windows 2000 system, or by authenticated attackers to execute arbitrary code with SYSTEM privileges on an affected Windows XP system.
Note : The Message Queuing component is not installed by default.