Reported April 4, 2002, by NSFocus.
Windows NT 4.0
A buffer overrun vulnerability exists in the Multiple Universal Naming Convention Provider (MUP) service that lets an attacker use the Local System security context to execute code on a vulnerable system. This vulnerability stems from the fact that the MUP service doesn't check inputs correctly before sending the second copy of the buffer contents to the redirector.
Discovered by NSFocus.