Vulnerability in SMB Parsing in ISS Products
Just saw this on bugtraq:
A vulnerability was discovered in the SMB (Server Message Block) protocol
parsing routines of the ISS Protocol Analysis Module (PAM) component found
in some ISS products. The flaw relates to incorrect parsing of the SMB
protocol, which may lead to a heap overflow condition.
eEye Digital Security has discovered a critical vulnerability in both
RealSecure and BlackICE. The vulnerability allows a remote attacker to
reliably overwrite heap memory with user-controlled data and execute
arbitrary code within the SYSTEM context. This attack will succeed with
BlackICE using its most paranoid settings.
You can read more here and EEYE's advisory