Description
Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as used in Microsoft Windows NT 4.0 SP6a, 2000 SP2 through SP4, XP SP1, Server 2003, NetMeeting, Windows 98, and Windows ME, allows remote attackers to execute arbitrary code via PCT 1.0 handshake packets.
Affected products
Exploits & proofs of concept
- exploit-dbMicrosoft Private Communications Transport - Remote Overflow (MS04-011) (Metasploit)by Metasploit
- exploit-dbMicrosoft IIS 5.0 - SSL Remote Buffer Overflow (MS04-011)by Johnny Cyberpunk
References
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1093
- MISChttp://www.securityfocus.com/archive/1/361836
- MISChttps://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-011
- MISChttp://www.kb.cert.org/vuls/id/586540
- MISChttp://www.us-cert.gov/cas/techalerts/TA04-104A.html
- MISChttp://xforce.iss.net/xforce/alerts/id/168
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A889
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A903
- MISChttps://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A951
Updated 21m ago · 8 sources