Double free vulnerability in the Workstation service in Microsoft Windows allows remote authenticated users to gain privileges via a crafted RPC message to a Windows XP SP2 or SP3 or Server 2003 SP2 system, or cause a denial of service via a crafted RPC message to a Vista Gold, SP1, or SP2 or Server 2008 Gold or SP2 system, aka "Workstation Service Memory Corruption Vulnerability."
Weaknesses in this category are related to improper management of system resources.
The product calls free() twice on the same memory address.
Link | Tags |
---|---|
http://www.us-cert.gov/cas/techalerts/TA09-223A.html | third party advisory us government resource |
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2009/ms09-041 | vendor advisory |
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A6286 | signature vdb entry |