CVE-2008-3466
Last modified
CVE-2008-3466 is a vulnerability of currently unknown severity. Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, which allows remote attackers to bypass authentication and execute arbitrary programs via a crafted SNA RPC message using opcode 1 or 6 to call the CreateProcess function, aka "HIS Command Execution Vulnerability.". EPSS estimates a 77.74% chance of exploitation in the next 30 days.
Description
Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, which allows remote attackers to bypass authentication and execute arbitrary programs via a crafted SNA RPC message using opcode 1 or 6 to call the CreateProcess function, aka "HIS Command Execution Vulnerability."
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Host Integration Server 2000 | All versions |
| Microsoft | Host Integration Server 2004 | All versions |
| Microsoft | Host Integration Server 2006 | All versions |
References
- http://secunia.com/advisories/32233Patch, Vendor Advisory
- http://www.securityfocus.com/bid/31620Exploit, Patch
- http://www.us-cert.gov/cas/techalerts/TA08-288A.htmlUS Government Resource
- http://secunia.com/advisories/32233Patch, Vendor Advisory
- http://www.securityfocus.com/bid/31620Exploit, Patch
- http://www.us-cert.gov/cas/techalerts/TA08-288A.htmlUS Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2008-3466?
How severe is CVE-2008-3466?
How do I fix CVE-2008-3466?
Are you affected by CVE-2008-3466?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
