CVE-2006-2371

Windows 2000 and 2003 Server - Remote Code Execution via RASMAN RPC Requests

Title source: llm
STIX 2.1

Description

Buffer overflow in the Remote Access Connection Manager service (RASMAN) service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 and earlier allows remote unauthenticated or authenticated attackers to execute arbitrary code via certain crafted "RPC related requests," that lead to registry corruption and stack corruption, aka the "RASMAN Registry Corruption Vulnerability."

References (17)

Core 17
Core References
Third Party Advisory third-party-advisory x_refsource_sreason
http://securityreason.com/securityalert/1096
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1983
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2006/2323
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/436977/100/0/threaded
US Government Resource third-party-advisory x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA06-164A.html
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/26436
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1674
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1907
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1851
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1857
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1016285
Patch, Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/20630
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/26814
Patch vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/18358
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/814644
Third Party Advisory, VDB Entry vdb-entry signature x_refsource_oval
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1846

Scores

EPSS 0.2260
EPSS Percentile 97.5%

Details

Status published
Products (12)
microsoft/windows_2000 (5 CPE variants)
microsoft/windows_2003_server datacenter_edition (2 CPE variants)
microsoft/windows_2003_server datacenter_edition_64-bit (2 CPE variants)
microsoft/windows_2003_server enterprise_64-bit
microsoft/windows_2003_server enterprise_edition sp1
microsoft/windows_2003_server enterprise_edition_64-bit (2 CPE variants)
microsoft/windows_2003_server r2
microsoft/windows_2003_server sp1
microsoft/windows_2003_server standard (2 CPE variants)
microsoft/windows_2003_server standard_64-bit
... and 2 more
Published Jun 13, 2006
Tracked Since Feb 18, 2026