Microsoft ASP.NET URI Canonicalization Unauthorized Web Access Vulnerability
BID:11342
Info
Microsoft ASP.NET URI Canonicalization Unauthorized Web Access Vulnerability
| Bugtraq ID: | 11342 |
| Class: | Input Validation Error |
| CVE: |
CVE-2004-0847 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 06 2004 12:00AM |
| Updated: | Oct 10 2007 11:48PM |
| Credit: | The vendor reported this vulnerability. |
| Vulnerable: |
Microsoft ASP.NET 1.1 Microsoft ASP.NET 1.0 Microsoft ASP.NET 0 Microsoft .NET Framework 1.1 SP1 Microsoft .NET Framework 1.1 Microsoft .NET Framework 1.0 SP3 Microsoft .NET Framework 1.0 SP2 Microsoft .NET Framework 1.0 SP1 Microsoft .NET Framework 1.0 |
| Not Vulnerable: | |
Discussion
Microsoft ASP.NET URI Canonicalization Unauthorized Web Access Vulnerability
Microsoft ASP.NET is reported prone to a remote information-disclosure vulnerability because the application fails to properly secure documents when handling malformed URI requests.
An attacker may leverage this issue to bypass authentication required to access files in secured directories.
Microsoft ASP.NET is reported prone to a remote information-disclosure vulnerability because the application fails to properly secure documents when handling malformed URI requests.
An attacker may leverage this issue to bypass authentication required to access files in secured directories.
Exploit / POC
Microsoft ASP.NET URI Canonicalization Unauthorized Web Access Vulnerability
No exploit is required to leverage this issue. The following proof of concept has been provided:
Mozilla Web Browser based proof of concept:
http://www.example.com/secureDirectory\somefile.aspx
Microsoft Internet Explorer based proof of concept:
http://www.example.com/secureDirectory%5Csomefile.aspx
No exploit is required to leverage this issue. The following proof of concept has been provided:
Mozilla Web Browser based proof of concept:
http://www.example.com/secureDirectory\somefile.aspx
Microsoft Internet Explorer based proof of concept:
http://www.example.com/secureDirectory%5Csomefile.aspx
Solution / Fix
Microsoft ASP.NET URI Canonicalization Unauthorized Web Access Vulnerability
Solution:
Microsoft has released updates to address this vulnerability.
Microsoft has updated their original advisory to indicate that a revised fix is available for .NET Framework on Windows XP Tablet Edition and Media Center Edition. At the time of this writing, the fix was not available from the download link provided in the bulletin.
Microsoft .NET Framework 1.0 SP3
Microsoft .NET Framework 1.0 SP2
Microsoft .NET Framework 1.1
Microsoft .NET Framework 1.1 SP1
Solution:
Microsoft has released updates to address this vulnerability.
Microsoft has updated their original advisory to indicate that a revised fix is available for .NET Framework on Windows XP Tablet Edition and Media Center Edition. At the time of this writing, the fix was not available from the download link provided in the bulletin.
Microsoft .NET Framework 1.0 SP3
-
Microsoft ASP.NET Security Update for Microsoft .NET Framework 1.0 Service Pack 3
This fix applies to .NET Framework 1.0 Service Pack 3 on the following platforms:Windows 2000 Service Pack 3 or Service Pack 4Windows XP Service Pack 1 or Windows XP Service Pack 2Windows Server 2003
http://www.microsoft.com/downloads/details.aspx?familyid=4E6D56E5-3D8D -423B-99A1-41EDF23D65BC&displaylang=en -
Microsoft ASP.NET Security Update for Microsoft .NET Framework 1.0 Service Pack 3 on Tablet PC / Media Center
This fix applies to .NET Framework 1.0 Service Pack 3 on the following platforms:Windows XP Tablet PC EditionWindows XP Media Center Edition
http://www.microsoft.com/downloads/details.aspx?familyid=EE611D27-52CF -43DB-BB97-21318C7FAA70&displaylang=en
Microsoft .NET Framework 1.0 SP2
-
Microsoft ASP.NET Security Update for Microsoft .NET Framework 1.0 Service Pack 2
This fix applies to .NET Framework 1.0 Service Pack 2 on the following platforms:Windows 2000 Service Pack 3 or Service Pack 4Windows XP Service Pack 1 or Windows XP Service Pack 2Windows Server 2003
http://www.microsoft.com/downloads/details.aspx?familyid=3271ACD5-EE3C -4BDF-AE28-56D2DF77151E&displaylang=en -
Microsoft ASP.NET Security Update for Microsoft .NET Framework 1.0 Service Pack 2 on Tablet PC / Media Center
This fix applies to .NET Framework 1.0 Service Pack 2 on the following platforms:Windows XP Tablet PC EditionWindows XP Media Center Edition
http://www.microsoft.com/downloads/details.aspx?familyid=33D4D33E-473F -4842-A3A8-C8266AEE8FAB&displaylang=en
Microsoft .NET Framework 1.1
-
Microsoft ASP.NET Security Update for Microsoft .NET Framework 1.1
This fix applies to .NET Framework 1.1 on the following platforms:Windows 2000 Service Pack 3 or Service Pack 4Windows XP Service Pack 1 or Windows XP Service Pack 2Windows XP Tablet PC EditionWindows XP Media Center Edition
http://www.microsoft.com/downloads/details.aspx?familyid=C5E19719-000F -456A-BEAB-5BD7949F8AA2&displaylang=en -
Microsoft ASP.NET Security Update for Microsoft .NET Framework 1.1 on Windows Server 2003
This fix applies to .NET Framework 1.1 on the following platform:Windows Server 2003
http://www.microsoft.com/downloads/details.aspx?familyid=E54BE8BE-22AF -4390-86E1-25D76794D5C7&displaylang=en
Microsoft .NET Framework 1.1 SP1
-
Microsoft ASP.NET Security Update for Microsoft .NET Framework 1.1 Service Pack 1
This fix applies to .NET Framework 1.1 Service Pack 1 on the following platforms:Windows 2000 Service Pack 3 or Service Pack 4Windows XP Service Pack 1 or Windows XP Service Pack 2Windows XP Tablet PC EditionWindows XP Media Center Edition
http://www.microsoft.com/downloads/details.aspx?familyid=8EC6FB8A-29EB -49CF-9DBC-1A0DC2273FF9&displaylang=en -
Microsoft ASP.NET Security Update for Microsoft .NET Framework 1.1 Service Pack 1 on Windows Server 2003
This fix applies to .NET Framework 1.1 Service Pack 1 on the following platform:Windows Server 2003
http://www.microsoft.com/downloads/details.aspx?familyid=9BBD5617-49AE -40BF-B0FA-F9049349C6F5&displaylang=en
References
Microsoft ASP.NET URI Canonicalization Unauthorized Web Access Vulnerability
References:
References: