Short Name |
MS-RPC:DCE-RPC-UUID-BIND |
---|---|
Severity |
Medium |
Recommended |
No |
Category |
MS-RPC |
Keywords |
UUID Bind |
Release Date |
2003/10/15 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to bind to the DCE-RPC UUID. Because the DCE-RPC UUID has many known vulnerabilities, this can indicate that an attacker is attempting to attack your network. NOTE: If your network environment has valid DCE-RPC traffic, this signature can produce false positives.
Successful RPC buffer overflow attacks result in arbitrary code execution and complete compromise of the affected host. Denial of service attacks are also possible, as RPC-dependent services frequently crash due to exploitation attempts.