Home / bulletins

MS08-059 – Critical: Vulnerability in Host Integration Server RPC Service Could Allow Remote Code Execution (956695) - Version:1.2

Posted on 29 October 2008

Critical

Severity Rating: Critical - Revision Note: V1.2 (October 29, 2008): Corrected the impact of the workaround that deals with disabling the SNA RPC Service. Summary: This security update resolves a privately reported vulnerability in Microsoft Host Integration Server. The vulnerability could allow remote code execution if an attacker sent a specially crafted Remote Procedure Call (RPC) request to an affected system. Customers who follow best practices and configure the SNA RPC service account to have fewer user rights on the system could be less impacted than customers who configure the SNA RPC service account to have administrative user rights.

Link

Other versions

 

TOP