Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-3vqg-cv53-whw6

Опубликовано: 02 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The Internet Authentication Service (IAS) in Microsoft Windows Vista SP2 and Server 2008 SP2 does not properly validate MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication requests, which allows remote attackers to execute arbitrary code via crafted structures in a malformed request, aka "Internet Authentication Service Memory Corruption Vulnerability."

The Internet Authentication Service (IAS) in Microsoft Windows Vista SP2 and Server 2008 SP2 does not properly validate MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication requests, which allows remote attackers to execute arbitrary code via crafted structures in a malformed request, aka "Internet Authentication Service Memory Corruption Vulnerability."

EPSS

Процентиль: 98%
0.47852
Средний

Дефекты

CWE-287

Связанные уязвимости

nvd
около 16 лет назад

The Internet Authentication Service (IAS) in Microsoft Windows Vista SP2 and Server 2008 SP2 does not properly validate MS-CHAP v2 Protected Extensible Authentication Protocol (PEAP) authentication requests, which allows remote attackers to execute arbitrary code via crafted structures in a malformed request, aka "Internet Authentication Service Memory Corruption Vulnerability."

EPSS

Процентиль: 98%
0.47852
Средний

Дефекты

CWE-287