Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.101011
Category:Windows : Microsoft Bulletins
Title:Microsoft Windows MS04-011 Security Check
Summary:Windows operating system are affected to multiple remote code; execution (RCE) and privileges escalation vulnerabilities.
Description:Summary:
Windows operating system are affected to multiple remote code
execution (RCE) and privileges escalation vulnerabilities.

Vulnerability Insight:
These vulnerabilities includes:

LSASS Remote Code Execution Vulnerability - CAN-2003-0533

LDAP Denial Of Service Vulnerability - CAN-2003-0663

PCT Remote Code Execution Vulnerability - CAN-2003-0719

Winlogon Remote Code Execution Vulnerability - CAN-2003-0806

Metafile Remote Code Execution Vulnerability - CAN-2003-0906

Help and Support Center Remote Code Execution Vulnerability - CAN-2003-0907

Utility Manager Privilege Elevation Vulnerability - CAN-2003-0908

Windows Management Privilege Elevation Vulnerability - CAN-2003-0909

Local Descriptor Table Privilege Elevation Vulnerability - CAN-2003-0910

H.323 Remote Code Execution Vulnerability - CAN-2004-0117

Virtual DOS Machine Privilege Elevation Vulnerability - CAN-2004-0118

Negotiate SSP Remote Code Execution Vulnerability - CAN-2004-0119

SSL Denial Of Service Vulnerability - CAN-2004-0120

ASN.1 Double Free Vulnerability - CAN-2004-0123.

Vulnerability Impact:
An attacker who successfully exploited the most severe of these vulnerabilities could take
complete control of an affected system, including:

- installing programs

- viewing, changing, or deleting data

- creating new accounts that have full privileges.

Solution:
Microsoft has released a patch to fix these issues.

CVSS Score:
7.6

CVSS Vector:
AV:N/AC:H/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2003-0533
BugTraq ID: 10108
http://www.securityfocus.com/bid/10108
Bugtraq: 20040429 MS04011 Lsasrv.dll RPC buffer overflow remote exploit (PoC) (Google Search)
http://marc.info/?l=bugtraq&m=108325860431471&w=2
Cert/CC Advisory: TA04-104A
http://www.us-cert.gov/cas/techalerts/TA04-104A.html
CERT/CC vulnerability note: VU#753212
http://www.kb.cert.org/vuls/id/753212
Computer Incident Advisory Center Bulletin: O-114
http://www.ciac.org/ciac/bulletins/o-114.shtml
eEye Security Advisory: AD20040413C
http://www.eeye.com/html/Research/Advisories/AD20040413C.html
http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020069.html
Microsoft Security Bulletin: MS04-011
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A883
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A898
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A919
XForce ISS Database: win-lsass-bo(15699)
https://exchange.xforce.ibmcloud.com/vulnerabilities/15699
Common Vulnerability Exposure (CVE) ID: CVE-2003-0663
BugTraq ID: 10114
http://www.securityfocus.com/bid/10114
CERT/CC vulnerability note: VU#639428
http://www.kb.cert.org/vuls/id/639428
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1016
XForce ISS Database: win2k-lsass-ldap-dos(15700)
https://exchange.xforce.ibmcloud.com/vulnerabilities/15700
Common Vulnerability Exposure (CVE) ID: CVE-2003-0719
Bugtraq: 20040430 A technical description of the SSL PCT vulnerability (CVE-2003-0719) (Google Search)
http://www.securityfocus.com/archive/1/361836
CERT/CC vulnerability note: VU#586540
http://www.kb.cert.org/vuls/id/586540
ISS Security Advisory: 20040413 Microsoft SSL Library Remote Compromise Vulnerability
http://xforce.iss.net/xforce/alerts/id/168
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1093
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A889
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A903
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A951
Common Vulnerability Exposure (CVE) ID: CVE-2003-0806
BugTraq ID: 10126
http://www.securityfocus.com/bid/10126
CERT/CC vulnerability note: VU#471260
http://www.kb.cert.org/vuls/id/471260
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1054
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A895
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A896
XForce ISS Database: win-winlogon-bo(15702)
https://exchange.xforce.ibmcloud.com/vulnerabilities/15702
Common Vulnerability Exposure (CVE) ID: CVE-2003-0906
BugTraq ID: 10120
http://www.securityfocus.com/bid/10120
CERT/CC vulnerability note: VU#547028
http://www.kb.cert.org/vuls/id/547028
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1064
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A897
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A959
Common Vulnerability Exposure (CVE) ID: CVE-2003-0907
BugTraq ID: 10119
http://www.securityfocus.com/bid/10119
Bugtraq: 20040413 [Full-Disclosure] iDEFENSE Security Advisory 04.13.04 - Microsoft Help and Support (Google Search)
http://marc.info/?l=bugtraq&m=108196864221676&w=2
CERT/CC vulnerability note: VU#260588
http://www.kb.cert.org/vuls/id/260588
http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020065.html
http://www.idefense.com/application/poi/display?id=100&type=vulnerabilities
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1000
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A904
XForce ISS Database: win-hcpurl-code-execution(15704)
https://exchange.xforce.ibmcloud.com/vulnerabilities/15704
Common Vulnerability Exposure (CVE) ID: CVE-2003-0908
BugTraq ID: 10124
http://www.securityfocus.com/bid/10124
CERT/CC vulnerability note: VU#526084
http://www.kb.cert.org/vuls/id/526084
http://www.appsecinc.com/resources/alerts/general/04-0001.html
http://www.securiteam.com/windowsntfocus/5LP0C2ACKU.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1046
http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0082.html
XForce ISS Database: win2k-utilitymgr-gain-privileges(15632)
https://exchange.xforce.ibmcloud.com/vulnerabilities/15632
Common Vulnerability Exposure (CVE) ID: CVE-2003-0909
BugTraq ID: 10125
http://www.securityfocus.com/bid/10125
CERT/CC vulnerability note: VU#206468
http://www.kb.cert.org/vuls/id/206468
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1004
XForce ISS Database: winxp-task-gain-privileges(15678)
https://exchange.xforce.ibmcloud.com/vulnerabilities/15678
Common Vulnerability Exposure (CVE) ID: CVE-2003-0910
BugTraq ID: 10122
http://www.securityfocus.com/bid/10122
CERT/CC vulnerability note: VU#122076
http://www.kb.cert.org/vuls/id/122076
eEye Security Advisory: AD20040413D
http://www.eeye.com/html/Research/Advisories/AD20040413D.html
http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020068.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A890
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A911
XForce ISS Database: win-ldt-gain-privileges(15707)
https://exchange.xforce.ibmcloud.com/vulnerabilities/15707
Common Vulnerability Exposure (CVE) ID: CVE-2004-0117
CERT/CC vulnerability note: VU#353956
http://www.kb.cert.org/vuls/id/353956
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A907
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A946
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A964
XForce ISS Database: win-h323-bo(15710)
https://exchange.xforce.ibmcloud.com/vulnerabilities/15710
Common Vulnerability Exposure (CVE) ID: CVE-2004-0118
BugTraq ID: 10117
http://www.securityfocus.com/bid/10117
CERT/CC vulnerability note: VU#783748
http://www.kb.cert.org/vuls/id/783748
eEye Security Advisory: AD20040413E
http://www.eeye.com/html/Research/Advisories/AD20040413E.html
http://lists.grok.org.uk/pipermail/full-disclosure/2004-April/020070.html
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1512
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1718
XForce ISS Database: win-vdm-gain-privileges(15714)
https://exchange.xforce.ibmcloud.com/vulnerabilities/15714
Common Vulnerability Exposure (CVE) ID: CVE-2004-0119
BugTraq ID: 10113
http://www.securityfocus.com/bid/10113
CERT/CC vulnerability note: VU#638548
http://www.kb.cert.org/vuls/id/638548
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1808
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1962
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1997
http://archives.neohapsis.com/archives/vulnwatch/2004-q1/0081.html
XForce ISS Database: win-spp-bo(15715)
https://exchange.xforce.ibmcloud.com/vulnerabilities/15715
Common Vulnerability Exposure (CVE) ID: CVE-2004-0120
BugTraq ID: 10115
http://www.securityfocus.com/bid/10115
CERT/CC vulnerability note: VU#150236
http://www.kb.cert.org/vuls/id/150236
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A885
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A886
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A892
XForce ISS Database: ssl-message-dos(15712)
https://exchange.xforce.ibmcloud.com/vulnerabilities/15712
Common Vulnerability Exposure (CVE) ID: CVE-2004-0123
BugTraq ID: 10118
http://www.securityfocus.com/bid/10118
CERT/CC vulnerability note: VU#255924
http://www.kb.cert.org/vuls/id/255924
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1007
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1076
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A924
XForce ISS Database: win-asn1-double-free(15713)
https://exchange.xforce.ibmcloud.com/vulnerabilities/15713
CopyrightCopyright (C) 2009 Christian Eric Edjenguele

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.