Thread-topic: [SA21851] Microsoft Windows Pragmatic General Multicast Code Execution
> TITLE:
> Microsoft Windows Pragmatic General Multicast Code Execution
>
> SECUNIA ADVISORY ID:
> SA21851
>
> VERIFY ADVISORY:
>
>
> CRITICAL:
> Moderately critical
>
> IMPACT:
> System access
>
> WHERE:
> From local network
>
> OPERATING SYSTEM:
> Microsoft Windows XP Home Edition
>
> Microsoft Windows XP Professional
>
>
> DESCRIPTION:
> A vulnerability has been reported in Microsoft Windows XP, which can
> be exploited by malicious people to compromise a vulnerable system.
>
> The vulnerability is caused due to an error in the handling of PGM
> (Pragmatic General Multicast) messages and can be exploited via a
> specially crafted multicast message.
>
> Successful exploitation allows execution of arbitrary code, but
> requires that the MSMQ (Microsoft Message Queuing) service is
> installed (not installed by default).
>
> SOLUTION:
> Apply patch.
>
> Microsoft Windows XP SP1/SP2:
>
> ac4-6ca3-4732-9016-3143ff1bca2f
>
> PROVIDED AND/OR DISCOVERED BY:
> The vendor credits David Warden, NuPaper.
>
> ORIGINAL ADVISORY:
> MS06-052 (KB919007):
>
>