Microsoft Windows WINS Association Context Data Remote Memory Corruption Vulnerability
BID:11763
Info
Microsoft Windows WINS Association Context Data Remote Memory Corruption Vulnerability
| Bugtraq ID: | 11763 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-1080 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 25 2004 12:00AM |
| Updated: | Jul 12 2009 08:06AM |
| Credit: | Discovery is credited to Nicolas Waisman; Kostya Kortchinsky also independently discovered this issue. |
| Vulnerable: |
Microsoft Windows Server 2003 Web Edition Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Enterprise Edition Itanium 0 Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Datacenter Edition Itanium 0 Microsoft Windows Server 2003 Datacenter Edition Microsoft Windows NT Terminal Server 4.0 SP6a Microsoft Windows NT Terminal Server 4.0 SP6 Microsoft Windows NT Terminal Server 4.0 SP5 Microsoft Windows NT Terminal Server 4.0 SP4 Microsoft Windows NT Terminal Server 4.0 SP3 Microsoft Windows NT Terminal Server 4.0 SP2 Microsoft Windows NT Terminal Server 4.0 SP1 Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6 Microsoft Windows NT Enterprise Server 4.0 SP5 Microsoft Windows NT Enterprise Server 4.0 SP4 Microsoft Windows NT Enterprise Server 4.0 SP3 Microsoft Windows NT Enterprise Server 4.0 SP2 Microsoft Windows NT Enterprise Server 4.0 SP1 Microsoft Windows NT Enterprise Server 4.0 Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server Microsoft Small Business Server 2003 Microsoft Small Business Server 2000 0 |
| Not Vulnerable: |
Microsoft Windows XP Professional SP2 Microsoft Windows XP Professional SP1 Microsoft Windows XP Home SP2 Microsoft Windows XP Home SP1 Microsoft Windows XP 64-bit Edition Version 2003 Microsoft Windows XP 64-bit Edition SP1 Microsoft Windows ME Microsoft Windows 98SE Microsoft Windows 98 SP1 Microsoft Windows 98 Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 |
Discussion
Microsoft Windows WINS Association Context Data Remote Memory Corruption Vulnerability
It is reported that the WINS replication protocol contains a vulnerability that when exploited will result in memory corruption. The issue exists due to a protocol design flaw that allows a remote user to specify the location of an association context data structure in memory.
Because the attacker may control the location of the data structure, this vulnerability may be exploited to corrupt process memory.
This issue could potentially be exploited remotely by a WINS client to execute arbitrary code with SYSTEM level privileges on a target WINS server. The service may be exposed via TCP/UDP port 42 by default, but the vendor has stated that other attack vectors may exist though none are known at this time.
The WINS service is not installed by default on most Microsoft Windows platforms.
** UPDATE: The WINS service is installed and enabled by default on Microsoft Small Business Server 2000/2003. However, the ports used for the service are reportedly not remotely accessible by default on Small Business Server.
It is reported that the WINS replication protocol contains a vulnerability that when exploited will result in memory corruption. The issue exists due to a protocol design flaw that allows a remote user to specify the location of an association context data structure in memory.
Because the attacker may control the location of the data structure, this vulnerability may be exploited to corrupt process memory.
This issue could potentially be exploited remotely by a WINS client to execute arbitrary code with SYSTEM level privileges on a target WINS server. The service may be exposed via TCP/UDP port 42 by default, but the vendor has stated that other attack vectors may exist though none are known at this time.
The WINS service is not installed by default on most Microsoft Windows platforms.
** UPDATE: The WINS service is installed and enabled by default on Microsoft Small Business Server 2000/2003. However, the ports used for the service are reportedly not remotely accessible by default on Small Business Server.
Exploit / POC
Microsoft Windows WINS Association Context Data Remote Memory Corruption Vulnerability
Immunitysec have developed a working commercial exploit for their CANVAS product. This exploit is not otherwise publicly available or known to be circulating in the wild.
CORE have developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Exploit has been released. 101-WINS-v3.cpp is an improved version of 101_WINS.cpp.
Immunitysec have developed a working commercial exploit for their CANVAS product. This exploit is not otherwise publicly available or known to be circulating in the wild.
CORE have developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Exploit has been released. 101-WINS-v3.cpp is an improved version of 101_WINS.cpp.
Solution / Fix
Microsoft Windows WINS Association Context Data Remote Memory Corruption Vulnerability
Solution:
Microsoft has released updates to address this vulnerability in supported versions of the Windows operating system.
Microsoft Windows Server 2003 Datacenter Edition
Microsoft Windows 2000 Advanced Server SP4
Microsoft Windows Server 2003 Enterprise Edition
Microsoft Windows NT Server 4.0 SP6a
Microsoft Windows Server 2003 Web Edition
Microsoft Windows 2000 Advanced Server SP3
Microsoft Windows Server 2003 Enterprise Edition Itanium 0
Microsoft Windows NT Terminal Server 4.0 SP6
Microsoft Windows 2000 Server SP3
Microsoft Windows Server 2003 Standard Edition
Microsoft Windows NT Enterprise Server 4.0 SP6a
Microsoft Windows 2000 Server SP4
Microsoft Windows Server 2003 Datacenter Edition Itanium 0
Solution:
Microsoft has released updates to address this vulnerability in supported versions of the Windows operating system.
Microsoft Windows Server 2003 Datacenter Edition
-
Microsoft Security Update for Windows Server 2003 (KB870763)
http://www.microsoft.com/downloads/details.aspx?familyid=10836F38-A38B -47D5-B87B-18D8E26EEFAA&displaylang=en
Microsoft Windows 2000 Advanced Server SP4
-
Microsoft Security Update for Windows 2000 (KB870763)
http://www.microsoft.com/downloads/details.aspx?familyid=40146B52-5546 -489E-857E-01FE1EF709B2&displaylang=en
Microsoft Windows Server 2003 Enterprise Edition
-
Microsoft Security Update for Windows Server 2003 (KB870763)
http://www.microsoft.com/downloads/details.aspx?familyid=10836F38-A38B -47D5-B87B-18D8E26EEFAA&displaylang=en
Microsoft Windows NT Server 4.0 SP6a
-
Microsoft Security Update for Windows NT (KB870763)
http://www.microsoft.com/downloads/details.aspx?familyid=38E9DB8C-5C43 -4E9A-9DC9-97C2686A45F1&displaylang=en
Microsoft Windows Server 2003 Web Edition
-
Microsoft Security Update for Windows Server 2003 (KB870763)
http://www.microsoft.com/downloads/details.aspx?familyid=10836F38-A38B -47D5-B87B-18D8E26EEFAA&displaylang=en
Microsoft Windows 2000 Advanced Server SP3
-
Microsoft Security Update for Windows 2000 (KB870763)
http://www.microsoft.com/downloads/details.aspx?familyid=40146B52-5546 -489E-857E-01FE1EF709B2&displaylang=en
Microsoft Windows Server 2003 Enterprise Edition Itanium 0
-
Microsoft Security Update for Windows Server 2003 64-bit Edition (KB870763)
http://www.microsoft.com/downloads/details.aspx?familyid=06CF9E85-C66D -4A7D-B2EB-99DE9423B60F&displaylang=en
Microsoft Windows NT Terminal Server 4.0 SP6
-
Microsoft Security Update for Windows NT Server 4.0, Terminal Server Edition (KB870763)
http://www.microsoft.com/downloads/details.aspx?familyid=D7AB3F6F-26FE -4AE8-A07A-481D772D03A6&displaylang=en
Microsoft Windows 2000 Server SP3
-
Microsoft Security Update for Windows 2000 (KB870763)
http://www.microsoft.com/downloads/details.aspx?familyid=40146B52-5546 -489E-857E-01FE1EF709B2&displaylang=en
Microsoft Windows Server 2003 Standard Edition
-
Microsoft Security Update for Windows Server 2003 (KB870763)
http://www.microsoft.com/downloads/details.aspx?familyid=10836F38-A38B -47D5-B87B-18D8E26EEFAA&displaylang=en
Microsoft Windows NT Enterprise Server 4.0 SP6a
-
Microsoft Security Update for Windows NT (KB870763)
http://www.microsoft.com/downloads/details.aspx?familyid=38E9DB8C-5C43 -4E9A-9DC9-97C2686A45F1&displaylang=en
Microsoft Windows 2000 Server SP4
-
Microsoft Security Update for Windows 2000 (KB870763)
http://www.microsoft.com/downloads/details.aspx?familyid=40146B52-5546 -489E-857E-01FE1EF709B2&displaylang=en
Microsoft Windows Server 2003 Datacenter Edition Itanium 0
-
Microsoft Security Update for Windows Server 2003 64-bit Edition (KB870763)
http://www.microsoft.com/downloads/details.aspx?familyid=06CF9E85-C66D -4A7D-B2EB-99DE9423B60F&displaylang=en
References
Microsoft Windows WINS Association Context Data Remote Memory Corruption Vulnerability
References:
References:
- [Dailydave] Happy Thanksgiving! (Dailydave)
- How to help protect against a WINS security issue (Microsoft)
- Microsoft Security Bulletin MS04-045 (Microsoft)
- Microsoft WINS Arbitrary Association delete exploit (CORE Security)
- Microsoft WINS Arbitrary Association Delete exploit (CORE Security Technologies)
- Wins.exe remote vulnerability. (Immunity, Inc.)
- Immunity, Inc Advisor (Nicolas Waisman
)