CVE Number | Vulnerability | Product | Severity | Date |
---|---|---|---|---|
MS14-062 | Vulnerability in Message Queuing Service Could Allow Elevation of Privilege (2993254) | Windows Server | Important | 15-10-2014 |
Technical Information
Brief overview of the risk:
A vulnerability exists in the Microsoft Message Queuing (MSMQ) service that could allow an attacker to elevate privileges on the targeted system.
Detailed Information on the risk:
The vulnerability could allow elevation of privilege if an attacker sends a specially crafted input/output control (IOCTL) request to the Message Queuing service. Successful exploitation of this vulnerability could lead to full access to the affected system. By default, the Message Queuing component is not installed on any affected operating system edition and can only be enabled by a user with administrative privileges.
Further information on this exploit is available at : MS14-062
Windows Server 2003 x64 Edition Service Pack 2
Windows Server 2003 with SP2 for Itanium-based Systems
Affected Software
Windows Server 2003 Service Pack 2Windows Server 2003 x64 Edition Service Pack 2
Windows Server 2003 with SP2 for Itanium-based Systems