Open/Create
Merge
Delete
Sanitize
SAINTwriter
By Severity
By Name
By Host
Scanning Options
Startup Options
Exploits
Tools
Search
Exploit Servers
Contents
Index
Search
Exploit - Windows Telephony API buffer overflow
06/12/2007
CVE-2005-0058
BID-14518
OSVDB-18606
Background
The Windows
Telephony API
(TAPI) provides telecommunications support for Windows applications.
The Problem
A buffer overflow in the Windows Telephony API allows local attackers to execute commands with administrative privileges.
Resolution
Apply the patch referenced in
Microsoft Security Bulletin 05-040
.
More Information
http://www.microsoft.com/technet/security/bulletin/ms05-040.mspx
Limitations
The Telephony service must be running on the target in order for this exploit to succeed.
Actions