Microsoft_RPCSS_Denial_of_Service_RPCSYSAC_badUNClen

Strike ID:
G04-33801
CVSS:
5.0 (AV:N/AC:L/Au:N/C:N/I:N/A:P)
False Positive:
f
Variants:
1
Year:
2004

Description

Due to incorrect handling of malformed RPC packets, a function in the RPCSS service that is responsible for the allocation of memory can be exploited remotely to exhaust all available memory on a vulnerable system. The RPCSS service is the Remote Procedure Call service running on Windows computers. The RPC service on the target system will no longer respond to requests. This may cause a denial of service condition for certain applications that rely on this service for network functionality. It is also believed that available memory on the target system will also decrease to very low levels, causing the entire system to become unusable.

CVE

References

Bid