A vulnerability exists in Network Dynamic Data Exchange NetDDE service for Microsoft Windows which could allow a remote attacker to compromise the affected system.
Impact
A remote unauthenticated attacker may be able to execute arbitrary code with administrative privileges on the vulnerable system. Microsoft reports that this vulnerability could also be used to attempt to perform a local elevation of privilege or remote denial of service.
Microsofts Network Dynamic Data Exchange NetDDE is a communication protocol that allows two Windows applications to communicate with each other over a network. A remote code execution Vulnerability exists in Microsoft NetDDE services caused due to an unchecked buffer. However these services are not started by default and would have to be manually started for an attacker to remotely exploit this vulnerability. An attacker who can deliver specially crafted packets to affected system can remotely exploit this vulnerability.
The information provided herein is on "as is" basis, without warranty of any kind.