Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista

Microsoft Windows Task Scheduler Remote Buffer Overflow Vulnerability

Microsoft Task Scheduler is reported prone to a remote stack-based buffer overflow vulnerability. The source of the vulnerability is that data in '.job' files is copied into an internal buffer without sufficient bounds checking.

It is reported that a remote attacker may exploit this vulnerability through Internet Explorer or Windows Explorer when the '.job' file is opened or a directory containing the file is rendered. The file could also be hosted on a share. Other attack vectors may also exist.

It should be noted that while this issue does not affect Windows NT 4.0 SP6a, it may affect this platform if Internet Explorer 6 SP1 is installed.







 

Privacy Statement
Copyright 2008, SecurityFocus