Short Name |
HTTP:STC:WINDOWS-FAX-COVER |
---|---|
Severity |
High |
Recommended |
No |
Recommended Action |
Drop |
Category |
HTTP |
Keywords |
Microsoft Windows Fax Services Cover Page Editor Heap Buffer Overflow |
Release Date |
2011/01/11 |
Update Number |
1846 |
Supported Platforms |
idp-4.0+, isg-3.1.134269+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known heap buffer overflow vulnerability in Microsoft Windows Fax Services. It is due to insufficient validation of a drawing object data while parsing Microsoft Fax cover page files. Remote attackers can exploit this by enticing the target user to open a specially crafted Fax cover page file. A successful attack can result in execution of arbitrary code within the security context of the currently logged in user. An unsuccessful attempt terminates the affected application abnormally.