Vulnerability

(MS14-062) Vulnerability in Message Queuing Service Could Allow Elevation of Privilege (2993254)

Publish date: November 11, 2014

CVE-2014-4971

SEVERITY

HIGH

//  ADVISORY DATE

11 NOV 2014


DESCRIPTION

This security update resolves a publicly disclosed vulnerability in Microsoft Windows. The vulnerability could allow elevation of privilege if an attacker sends a specially crafted input/output control (IOCTL) request to the Message Queuing service. Successful exploitation of this vulnerability could lead to full access to the affected system. By default, the Message Queuing component is not installed on any affected operating system edition and can only be enabled by a user with administrative privileges. Only customers who manually enable the Message Queuing component are likely to be vulnerable to this issue.

SOLUTION

AFFECTED SOFTWARE AND VERSION

  • Windows Server 2003 Service Pack 2
  • Windows Server 2003 x64 Edition Service Pack 2
  • Windows Server 2003 with SP2 for Itanium-based Systems

Featured Stories

Connect with us on