Microsoft Windows WINS Name Value Handling Remote Buffer Overflow Vulnerability
BID:11922
Info
Microsoft Windows WINS Name Value Handling Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 11922 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2004-0567 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 14 2004 12:00AM |
| Updated: | Nov 01 2007 05:06PM |
| Credit: | This vulnerability was reported to Microsoft by Kostya Kortchinsky. |
| Vulnerable: |
Microsoft Windows Server 2003 Web Edition SP1 Beta 1 Microsoft Windows Server 2003 Web Edition Microsoft Windows Server 2003 Standard Edition SP1 Beta 1 Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Enterprise Edition Itanium SP1 Beta 1 Microsoft Windows Server 2003 Enterprise Edition Itanium 0 Microsoft Windows Server 2003 Enterprise Edition SP1 Beta 1 Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Datacenter Edition Itanium SP1 Beta 1 Microsoft Windows Server 2003 Datacenter Edition Itanium 0 Microsoft Windows Server 2003 Datacenter Edition SP1 Beta 1 Microsoft Windows Server 2003 Datacenter Edition Microsoft Windows NT Terminal Server 4.0 SP6 Microsoft Windows NT Terminal Server 4.0 SP5 Microsoft Windows NT Terminal Server 4.0 SP4 Microsoft Windows NT Terminal Server 4.0 SP3 Microsoft Windows NT Terminal Server 4.0 SP2 Microsoft Windows NT Terminal Server 4.0 SP1 Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6 Microsoft Windows NT Enterprise Server 4.0 SP5 Microsoft Windows NT Enterprise Server 4.0 SP4 Microsoft Windows NT Enterprise Server 4.0 SP3 Microsoft Windows NT Enterprise Server 4.0 SP2 Microsoft Windows NT Enterprise Server 4.0 SP1 Microsoft Windows NT Enterprise Server 4.0 Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: |
Microsoft Windows XP Professional SP2 Microsoft Windows XP Professional SP1 Microsoft Windows XP Home SP2 Microsoft Windows XP Home SP1 Microsoft Windows XP 64-bit Edition Version 2003 Microsoft Windows XP 64-bit Edition SP1 Microsoft Windows ME Microsoft Windows 98SE Microsoft Windows 98 SP1 Microsoft Windows 98 Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 |
Discussion
Microsoft Windows WINS Name Value Handling Remote Buffer Overflow Vulnerability
The WINS server contains a buffer-overflow vulnerability that can allow attackers to corrupt WINS process memory. The issue occurs because the software fails to perform sufficient boundary checks on computer 'name' data that is handled during a WINS transaction.
Ultimately, a WINS client may exploit this issue remotely to execute arbitrary code with SYSTEM-level privileges on a target WINS server. The service may be exposed via TCP/UDP port 42 by default, but the vendor has stated that other attack vectors may exist (though none are known at this time).
The WINS server contains a buffer-overflow vulnerability that can allow attackers to corrupt WINS process memory. The issue occurs because the software fails to perform sufficient boundary checks on computer 'name' data that is handled during a WINS transaction.
Ultimately, a WINS client may exploit this issue remotely to execute arbitrary code with SYSTEM-level privileges on a target WINS server. The service may be exposed via TCP/UDP port 42 by default, but the vendor has stated that other attack vectors may exist (though none are known at this time).
Exploit / POC
Microsoft Windows WINS Name Value Handling Remote Buffer Overflow Vulnerability
An exploit has been released as part of the MetaSploit Framework 2.3.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
An exploit has been released as part of the MetaSploit Framework 2.3.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft Windows WINS Name Value Handling Remote Buffer Overflow Vulnerability
Solution:
Microsoft has released updates to address this vulnerability in supported versions of the Windows operating system.
Microsoft Windows Server 2003 Datacenter Edition
Microsoft Windows 2000 Advanced Server SP4
Microsoft Windows NT Server 4.0 SP6a
Microsoft Windows Server 2003 Enterprise Edition
Microsoft Windows Server 2003 Web Edition
Microsoft Windows 2000 Advanced Server SP3
Microsoft Windows Server 2003 Enterprise Edition Itanium 0
Microsoft Windows 2000 Server SP3
Microsoft Windows NT Terminal Server 4.0 SP6
Microsoft Windows Server 2003 Standard Edition
Microsoft Windows NT Enterprise Server 4.0 SP6a
Microsoft Windows 2000 Server SP4
Microsoft Windows Server 2003 Datacenter Edition Itanium 0
Solution:
Microsoft has released updates to address this vulnerability in supported versions of the Windows operating system.
Microsoft Windows Server 2003 Datacenter Edition
-
Microsoft Security Update for Windows Server 2003 (KB870763)
http://www.microsoft.com/downloads/details.aspx?familyid=10836F38-A38B -47D5-B87B-18D8E26EEFAA&displaylang=en
Microsoft Windows 2000 Advanced Server SP4
-
Microsoft Security Update for Windows 2000 (KB870763)
http://www.microsoft.com/downloads/details.aspx?familyid=40146B52-5546 -489E-857E-01FE1EF709B2&displaylang=en
Microsoft Windows NT Server 4.0 SP6a
-
Microsoft Security Update for Windows NT (KB870763)
http://www.microsoft.com/downloads/details.aspx?familyid=38E9DB8C-5C43 -4E9A-9DC9-97C2686A45F1&displaylang=en
Microsoft Windows Server 2003 Enterprise Edition
-
Microsoft Security Update for Windows Server 2003 (KB870763)
http://www.microsoft.com/downloads/details.aspx?familyid=10836F38-A38B -47D5-B87B-18D8E26EEFAA&displaylang=en
Microsoft Windows Server 2003 Web Edition
-
Microsoft Security Update for Windows Server 2003 (KB870763)
http://www.microsoft.com/downloads/details.aspx?familyid=10836F38-A38B -47D5-B87B-18D8E26EEFAA&displaylang=en
Microsoft Windows 2000 Advanced Server SP3
-
Microsoft Security Update for Windows 2000 (KB870763)
http://www.microsoft.com/downloads/details.aspx?familyid=40146B52-5546 -489E-857E-01FE1EF709B2&displaylang=en
Microsoft Windows Server 2003 Enterprise Edition Itanium 0
-
Microsoft Security Update for Windows Server 2003 64-bit Edition (KB870763)
http://www.microsoft.com/downloads/details.aspx?familyid=06CF9E85-C66D -4A7D-B2EB-99DE9423B60F&displaylang=en
Microsoft Windows 2000 Server SP3
-
Microsoft Security Update for Windows 2000 (KB870763)
http://www.microsoft.com/downloads/details.aspx?familyid=40146B52-5546 -489E-857E-01FE1EF709B2&displaylang=en
Microsoft Windows NT Terminal Server 4.0 SP6
-
Microsoft Security Update for Windows NT Server 4.0, Terminal Server Edition (KB870763)
http://www.microsoft.com/downloads/details.aspx?familyid=D7AB3F6F-26FE -4AE8-A07A-481D772D03A6&displaylang=en
Microsoft Windows Server 2003 Standard Edition
-
Microsoft Security Update for Windows Server 2003 (KB870763)
http://www.microsoft.com/downloads/details.aspx?familyid=10836F38-A38B -47D5-B87B-18D8E26EEFAA&displaylang=en
Microsoft Windows NT Enterprise Server 4.0 SP6a
-
Microsoft Security Update for Windows NT (KB870763)
http://www.microsoft.com/downloads/details.aspx?familyid=38E9DB8C-5C43 -4E9A-9DC9-97C2686A45F1&displaylang=en
Microsoft Windows 2000 Server SP4
-
Microsoft Security Update for Windows 2000 (KB870763)
http://www.microsoft.com/downloads/details.aspx?familyid=40146B52-5546 -489E-857E-01FE1EF709B2&displaylang=en
Microsoft Windows Server 2003 Datacenter Edition Itanium 0
-
Microsoft Security Update for Windows Server 2003 64-bit Edition (KB870763)
http://www.microsoft.com/downloads/details.aspx?familyid=06CF9E85-C66D -4A7D-B2EB-99DE9423B60F&displaylang=en
References
Microsoft Windows WINS Name Value Handling Remote Buffer Overflow Vulnerability
References:
References:
- Metasploit Framework Exploits (Metasploit)
- Microsoft Security Bulletin MS04-045 (Microsoft)
- Microsoft WINS Name Validation exploit (CORE Security)