=====================================================================
                                    CERT-Renater

                         Note d'Information No. 2006/VULN555
_____________________________________________________________________

DATE                      : 13/12/2006

HARDWARE PLATFORM(S)      : /

OPERATING SYSTEM(S)       : Windows systems running SNMP.

======================================================================

MS06-074 - Vulnerability in SNMP Could Allow Remote Code Execution (926247)

Affected Software:
  - Microsoft Windows 2000 Service Pack 4
  - Microsoft Windows XP Service Pack 2
  - Microsoft Windows XP Professional x64 Edition
  - Microsoft Windows Server 2003
  - Microsoft Windows Server 2003 Service Pack 1
  - Microsoft Windows Server 2003 for Itanium-based Systems
  - Microsoft Windows Server 2003 with SP1 for Itanium-based Systems
  - Microsoft Windows Server 2003 x64 Edition

Full MS06-074 Advisory:
   http://www.microsoft.com/technet/security/Bulletin/MS06-074.mspx

Vulnerability Details

SNMP Memory Corruption Vulnerability
CVE-2006-5583

A remote code execution vulnerability exists in SNMP Service that could allow
an attacker who successfully exploited this vulnerability to take complete
control of the affected system.

======================================================================

           =========================================================
           Les serveurs de référence du CERT-Renater
           http://www.urec.fr/securite
           http://www.cru.fr/securite
           http://www.renater.fr
           =========================================================
           + CERT-RENATER          | tel : 01-53-94-20-44          +
           + 151 bd de l'Hopital   | fax : 01-53-94-20-41          +
           + 75013 Paris           | email: certsvp@renater.fr     +
           =========================================================





