A buffer overflow in Smart Card authentication code in gpkcsp.dll in Microsoft Windows XP through SP3 and Server 2003 through SP2 allows a remote attacker to execute arbitrary code on the target computer, provided that the computer is joined in a Windows domain and has Remote Desktop Protocol connectivity (or Terminal Services) enabled.
CVSS Details
- CVSS 3.0 Base Score: 8.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Msft | — | Security Update for Windows Server 2003 for x64-based Systems (KB4022747)Security Update for Windows Server 2003 (KB4022747)Security Update for Windows XP SP3 for XPe (KB4022747)Security Update for Windows XP SP2 for x64-based Systems (KB4022747)Security Update for Windows XP SP3 (KB4022747)Security Update for WES09 and POSReady 2009 (KB4022747) | Jun 14, 2017 | Jun 14, 2017 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub