Microsoft Windows Task Scheduler Remote Buffer Overflow Vulnerability
BID:10708
Info
Microsoft Windows Task Scheduler Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 10708 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0212 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 13 2004 12:00AM |
| Updated: | Jul 12 2009 06:16AM |
| Credit: | Discovery of this vulnerability is credited to Brett Moore of Security-Assessment.com, Dustin Schneider, and Peter Winter-Smith of Next Generation Security Software Ltd. |
| Vulnerable: |
Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows XP 64-bit Edition Version 2003 SP1 Microsoft Windows XP 64-bit Edition Version 2003 Microsoft Windows XP 64-bit Edition SP1 Microsoft Windows XP 64-bit Edition Microsoft Windows NT Workstation 4.0 SP6a Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 Avaya S8100 Media Servers 0 Avaya S3400 Message Application Server 0 Avaya IP600 Media Servers Avaya DefinityOne Media Servers |
| Not Vulnerable: | |
Discussion
Microsoft Windows Task Scheduler Remote Buffer Overflow Vulnerability
Microsoft Task Scheduler is reported prone to a remote stack-based buffer overflow vulnerability. The source of the vulnerability is that data in '.job' files is copied into an internal buffer without sufficient bounds checking.
It is reported that a remote attacker may exploit this vulnerability through Internet Explorer or Windows Explorer when the '.job' file is opened or a directory containing the file is rendered. The file could also be hosted on a share. Other attack vectors may also exist.
It should be noted that while this issue does not affect Windows NT 4.0 SP6a, it may affect this platform if Internet Explorer 6 SP1 is installed.
Microsoft Task Scheduler is reported prone to a remote stack-based buffer overflow vulnerability. The source of the vulnerability is that data in '.job' files is copied into an internal buffer without sufficient bounds checking.
It is reported that a remote attacker may exploit this vulnerability through Internet Explorer or Windows Explorer when the '.job' file is opened or a directory containing the file is rendered. The file could also be hosted on a share. Other attack vectors may also exist.
It should be noted that while this issue does not affect Windows NT 4.0 SP6a, it may affect this platform if Internet Explorer 6 SP1 is installed.
Exploit / POC
Microsoft Windows Task Scheduler Remote Buffer Overflow Vulnerability
The researchers who discovered this vulnerability have developed working exploit code that is not publicly available or known to be circulating in the wild.
The following exploits, which target Windows XP, have been released to the public:
The researchers who discovered this vulnerability have developed working exploit code that is not publicly available or known to be circulating in the wild.
The following exploits, which target Windows XP, have been released to the public:
Solution / Fix
Microsoft Windows Task Scheduler Remote Buffer Overflow Vulnerability
Solution:
Microsoft has released a security bulletin (MS04-022) and fixes to address this issue for supported operating systems.
Avaya has released an advisory that acknowledges this vulnerability for Avaya products. Avaya advise that customers follow the Microsoft recommendations to address this issue. Please see the referenced Avaya advisory at the following location for further details:
http://support.avaya.com/japple/css/japple?temp.groupID=128450&temp.selectedFamily=128451&temp.selectedProduct=154235&temp.selectedBucket=126655&temp.feedbackState=askForFeedback&temp.documentID=197331&PAGE=avaya.css.CSSLvl1Detail&executeTransaction=avaya.css.UsageUpdate()
Microsoft Windows 2000 Server SP2
Microsoft Windows 2000 Advanced Server SP1
Microsoft Windows 2000 Advanced Server SP2
Microsoft Windows NT Workstation 4.0 SP6a
Microsoft Windows XP 64-bit Edition SP1
Microsoft Windows 2000 Advanced Server SP4
Microsoft Windows 2000 Professional SP3
Microsoft Windows NT Server 4.0 SP6a
Microsoft Windows 2000 Professional SP2
Microsoft Windows 2000 Professional
Microsoft Windows XP Home
Microsoft Windows 2000 Advanced Server SP3
Microsoft Windows XP Home SP1
Microsoft Windows XP 64-bit Edition Version 2003 SP1
Microsoft Windows 2000 Professional SP1
Microsoft Windows 2000 Server SP3
Microsoft Windows XP 64-bit Edition Version 2003
Microsoft Windows NT Enterprise Server 4.0 SP6a
Microsoft Windows XP 64-bit Edition
Microsoft Windows 2000 Server SP4
Microsoft Windows 2000 Server SP1
Microsoft Windows 2000 Professional SP4
Microsoft Windows XP Professional
Microsoft Windows XP Professional SP1
Microsoft Windows 2000 Advanced Server
Microsoft Windows 2000 Server
Solution:
Microsoft has released a security bulletin (MS04-022) and fixes to address this issue for supported operating systems.
Avaya has released an advisory that acknowledges this vulnerability for Avaya products. Avaya advise that customers follow the Microsoft recommendations to address this issue. Please see the referenced Avaya advisory at the following location for further details:
http://support.avaya.com/japple/css/japple?temp.groupID=128450&temp.selectedFamily=128451&temp.selectedProduct=154235&temp.selectedBucket=126655&temp.feedbackState=askForFeedback&temp.documentID=197331&PAGE=avaya.css.CSSLvl1Detail&executeTransaction=avaya.css.UsageUpdate()
Microsoft Windows 2000 Server SP2
-
Microsoft Security Update for Windows 2000 (KB841873)
http://www.microsoft.com/downloads/details.aspx?FamilyId=BBF3C8A1-7D72 -4CE9-A586-7C837B499C08&displaylang=en
Microsoft Windows 2000 Advanced Server SP1
-
Microsoft Security Update for Windows 2000 (KB841873)
http://www.microsoft.com/downloads/details.aspx?FamilyId=BBF3C8A1-7D72 -4CE9-A586-7C837B499C08&displaylang=en
Microsoft Windows 2000 Advanced Server SP2
-
Microsoft Security Update for Windows 2000 (KB841873)
http://www.microsoft.com/downloads/details.aspx?FamilyId=BBF3C8A1-7D72 -4CE9-A586-7C837B499C08&displaylang=en
Microsoft Windows NT Workstation 4.0 SP6a
-
Microsoft Security Update for Windows NT4 (KB841873)
This update applies to Windows NT 4.0 SP6A when Internet Explorer 6 Service Pack 1 is installed.
http://www.microsoft.com/downloads/details.aspx?FamilyId=D4F57F82-D2BA -411A-8B40-77A3D80E58AC&displaylang=en
Microsoft Windows XP 64-bit Edition SP1
-
Microsoft Security Update for Windows XP 64-bit Edition (KB841873)
http://www.microsoft.com/downloads/details.aspx?FamilyId=7B4AC0FA-7954 -4993-85A1-85298F122CE0&displaylang=en
Microsoft Windows 2000 Advanced Server SP4
-
Microsoft Security Update for Windows 2000 (KB841873)
http://www.microsoft.com/downloads/details.aspx?FamilyId=BBF3C8A1-7D72 -4CE9-A586-7C837B499C08&displaylang=en
Microsoft Windows 2000 Professional SP3
-
Microsoft Security Update for Windows 2000 (KB841873)
http://www.microsoft.com/downloads/details.aspx?FamilyId=BBF3C8A1-7D72 -4CE9-A586-7C837B499C08&displaylang=en
Microsoft Windows NT Server 4.0 SP6a
-
Microsoft Security Update for Windows NT4 (KB841873)
This update applies to Windows NT 4.0 SP6A when Internet Explorer 6 Service Pack 1 is installed.
http://www.microsoft.com/downloads/details.aspx?FamilyId=D4F57F82-D2BA -411A-8B40-77A3D80E58AC&displaylang=en
Microsoft Windows 2000 Professional SP2
-
Microsoft Security Update for Windows 2000 (KB841873)
http://www.microsoft.com/downloads/details.aspx?FamilyId=BBF3C8A1-7D72 -4CE9-A586-7C837B499C08&displaylang=en
Microsoft Windows 2000 Professional
-
Microsoft Security Update for Windows 2000 (KB841873)
http://www.microsoft.com/downloads/details.aspx?FamilyId=BBF3C8A1-7D72 -4CE9-A586-7C837B499C08&displaylang=en
Microsoft Windows XP Home
-
Microsoft Security Update for Windows XP (KB841873)
http://www.microsoft.com/downloads/details.aspx?FamilyId=8E8D0A2D-D3B9 -4DE8-8B6F-FC27715BC0CF&displaylang=en
Microsoft Windows 2000 Advanced Server SP3
-
Microsoft Security Update for Windows 2000 (KB841873)
http://www.microsoft.com/downloads/details.aspx?FamilyId=BBF3C8A1-7D72 -4CE9-A586-7C837B499C08&displaylang=en
Microsoft Windows XP Home SP1
-
Microsoft Security Update for Windows XP (KB841873)
http://www.microsoft.com/downloads/details.aspx?FamilyId=8E8D0A2D-D3B9 -4DE8-8B6F-FC27715BC0CF&displaylang=en
Microsoft Windows XP 64-bit Edition Version 2003 SP1
-
Microsoft Security Update for Windows XP 64-bit Edition (KB841873)
http://www.microsoft.com/downloads/details.aspx?FamilyId=7B4AC0FA-7954 -4993-85A1-85298F122CE0&displaylang=en
Microsoft Windows 2000 Professional SP1
-
Microsoft Security Update for Windows 2000 (KB841873)
http://www.microsoft.com/downloads/details.aspx?FamilyId=BBF3C8A1-7D72 -4CE9-A586-7C837B499C08&displaylang=en
Microsoft Windows 2000 Server SP3
-
Microsoft Security Update for Windows 2000 (KB841873)
http://www.microsoft.com/downloads/details.aspx?FamilyId=BBF3C8A1-7D72 -4CE9-A586-7C837B499C08&displaylang=en
Microsoft Windows XP 64-bit Edition Version 2003
-
Microsoft Security Update for Windows XP 64-bit Edition (KB841873)
http://www.microsoft.com/downloads/details.aspx?FamilyId=7B4AC0FA-7954 -4993-85A1-85298F122CE0&displaylang=en
Microsoft Windows NT Enterprise Server 4.0 SP6a
-
Microsoft Security Update for Windows NT4 (KB841873)
This update applies to Windows NT 4.0 SP6A when Internet Explorer 6 Service Pack 1 is installed.
http://www.microsoft.com/downloads/details.aspx?FamilyId=D4F57F82-D2BA -411A-8B40-77A3D80E58AC&displaylang=en
Microsoft Windows XP 64-bit Edition
-
Microsoft Security Update for Windows XP 64-bit Edition (KB841873)
http://www.microsoft.com/downloads/details.aspx?FamilyId=7B4AC0FA-7954 -4993-85A1-85298F122CE0&displaylang=en
Microsoft Windows 2000 Server SP4
-
Microsoft Security Update for Windows 2000 (KB841873)
http://www.microsoft.com/downloads/details.aspx?FamilyId=BBF3C8A1-7D72 -4CE9-A586-7C837B499C08&displaylang=en
Microsoft Windows 2000 Server SP1
-
Microsoft Security Update for Windows 2000 (KB841873)
http://www.microsoft.com/downloads/details.aspx?FamilyId=BBF3C8A1-7D72 -4CE9-A586-7C837B499C08&displaylang=en
Microsoft Windows 2000 Professional SP4
-
Microsoft Security Update for Windows 2000 (KB841873)
http://www.microsoft.com/downloads/details.aspx?FamilyId=BBF3C8A1-7D72 -4CE9-A586-7C837B499C08&displaylang=en
Microsoft Windows XP Professional
-
Microsoft Security Update for Windows XP (KB841873)
http://www.microsoft.com/downloads/details.aspx?FamilyId=8E8D0A2D-D3B9 -4DE8-8B6F-FC27715BC0CF&displaylang=en
Microsoft Windows XP Professional SP1
-
Microsoft Security Update for Windows XP (KB841873)
http://www.microsoft.com/downloads/details.aspx?FamilyId=8E8D0A2D-D3B9 -4DE8-8B6F-FC27715BC0CF&displaylang=en
Microsoft Windows 2000 Advanced Server
-
Microsoft Security Update for Windows 2000 (KB841873)
http://www.microsoft.com/downloads/details.aspx?FamilyId=BBF3C8A1-7D72 -4CE9-A586-7C837B499C08&displaylang=en
Microsoft Windows 2000 Server
-
Microsoft Security Update for Windows 2000 (KB841873)
http://www.microsoft.com/downloads/details.aspx?FamilyId=BBF3C8A1-7D72 -4CE9-A586-7C837B499C08&displaylang=en
References
Microsoft Windows Task Scheduler Remote Buffer Overflow Vulnerability
References:
References:
- Microsoft Security Bulletin MS04-022 (Microsoft)
- Technical Cyber Security Alert TA04-196A (CERT/CC)
- Vulnerability Note VU#228028 (CERT/CC)
- [EXPL] (MS04-022) Microsoft Windows XP Task Scheduler (.job) Universal Exploit (houseofdabus HOD
) - Microsoft Windows Task Scheduler '.job' Stack Overflow (NGSSoftware Insight Security Research
) - RE: Unchecked buffer in mstask.dll ("Thor Larholm"
) - Unchecked buffer in mstask.dll ("Brett Moore"
)