Microsoft Windows License Logging Service Buffer Overflow Vulnerability
BID:12481
Info
Microsoft Windows License Logging Service Buffer Overflow Vulnerability
| Bugtraq ID: | 12481 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2005-0050 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 08 2005 12:00AM |
| Updated: | Jul 12 2009 10:06AM |
| Credit: | Discovery is credited to Kostya Kortchinsky <[email protected]>. |
| Vulnerable: |
Nortel Networks Symposium Web Client Nortel Networks Symposium Web Center Portal (SWCP) Nortel Networks Symposium TAPI Service Provider Nortel Networks Symposium Network Control Center (NCC) Nortel Networks Symposium Express Call Center (SECC) Nortel Networks Symposium Agent Greeting Nortel Networks Symposium Agent Nortel Networks Optivity Telephony Manager (OTM) Nortel Networks Mobile Voice Client 2050 Nortel Networks IP softphone 2050 Microsoft Windows Server 2003 Web Edition Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Enterprise Edition Itanium 0 Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Datacenter Edition Itanium 0 Microsoft Windows Server 2003 Datacenter Edition Microsoft Windows NT Terminal Server 4.0 SP6a Microsoft Windows NT Terminal Server 4.0 SP6 Microsoft Windows NT Terminal Server 4.0 SP5 Microsoft Windows NT Terminal Server 4.0 SP4 Microsoft Windows NT Terminal Server 4.0 SP3 Microsoft Windows NT Terminal Server 4.0 SP2 Microsoft Windows NT Terminal Server 4.0 SP1 Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6 Microsoft Windows NT Enterprise Server 4.0 SP5 Microsoft Windows NT Enterprise Server 4.0 SP4 Microsoft Windows NT Enterprise Server 4.0 SP3 Microsoft Windows NT Enterprise Server 4.0 SP2 Microsoft Windows NT Enterprise Server 4.0 SP1 Microsoft Windows NT Enterprise Server 4.0 Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server Microsoft Small Business Server 2003 Microsoft Small Business Server 2000 0 |
| Not Vulnerable: | |
Discussion
Microsoft Windows License Logging Service Buffer Overflow Vulnerability
A buffer overflow exists in the Microsoft Windows License Logging Service. This could allow remote execution of arbitrary code.
A buffer overflow exists in the Microsoft Windows License Logging Service. This could allow remote execution of arbitrary code.
Exploit / POC
Microsoft Windows License Logging Service Buffer Overflow Vulnerability
An exploit is available for the IMMUNITY, Inc. CANVAS penetration-testing framework. Licensed users of CANVAS have access to the exploit.
An exploit is available for the IMMUNITY, Inc. CANVAS penetration-testing framework. Licensed users of CANVAS have access to the exploit.
Solution / Fix
Microsoft Windows License Logging Service Buffer Overflow Vulnerability
Solution:
Microsoft has released updates to address supported platforms.
Nortel Networks has released security advisory 2005005510-2 acknowledging
this issue. Please see the referenced advisory for further information.
Microsoft Windows Server 2003 Datacenter Edition
Microsoft Windows 2000 Advanced Server SP4
Microsoft Small Business Server 2003
Microsoft Small Business Server 2000 0
Microsoft Windows NT Server 4.0 SP6a
Microsoft Windows Server 2003 Enterprise Edition
Microsoft Windows 2000 Datacenter Server SP4
Microsoft Windows Server 2003 Web Edition
Microsoft Windows 2000 Advanced Server SP3
Microsoft Windows 2000 Datacenter Server SP3
Microsoft Windows Server 2003 Enterprise Edition Itanium 0
Microsoft Windows 2000 Server SP3
Microsoft Windows NT Terminal Server 4.0 SP6
Microsoft Windows Server 2003 Standard Edition
Microsoft Windows NT Enterprise Server 4.0 SP6a
Microsoft Windows 2000 Server SP4
Microsoft Windows Server 2003 Datacenter Edition Itanium 0
Solution:
Microsoft has released updates to address supported platforms.
Nortel Networks has released security advisory 2005005510-2 acknowledging
this issue. Please see the referenced advisory for further information.
Microsoft Windows Server 2003 Datacenter Edition
-
Microsoft Security Update for Windows Server 2003 (KB885834)
http://www.microsoft.com/downloads/details.aspx?familyid=06EAF8E3-CCB7 -482B-8B68-340521150113&displaylang=en
Microsoft Windows 2000 Advanced Server SP4
-
Microsoft Security Update for Windows 2000 (KB885834)
http://www.microsoft.com/downloads/details.aspx?familyid=E9983AA2-2CEC -4B62-80D6-8E966A83A5D1&displaylang=en
Microsoft Small Business Server 2003
-
Microsoft Security Update for Windows Server 2003 (KB885834)
http://www.microsoft.com/downloads/details.aspx?familyid=06EAF8E3-CCB7 -482B-8B68-340521150113&displaylang=en
Microsoft Small Business Server 2000 0
-
Microsoft Security Update for Windows 2000 (KB885834)
http://www.microsoft.com/downloads/details.aspx?familyid=E9983AA2-2CEC -4B62-80D6-8E966A83A5D1&displaylang=en
Microsoft Windows NT Server 4.0 SP6a
-
Microsoft Security Update for Windows NT Server 4.0 (KB885834)
http://www.microsoft.com/downloads/details.aspx?familyid=817FDC2D-AEE2 -4FAF-908B-197B65A471F2&displaylang=en
Microsoft Windows Server 2003 Enterprise Edition
-
Microsoft Security Update for Windows Server 2003 (KB885834)
http://www.microsoft.com/downloads/details.aspx?familyid=06EAF8E3-CCB7 -482B-8B68-340521150113&displaylang=en
Microsoft Windows 2000 Datacenter Server SP4
-
Microsoft Security Update for Windows 2000 (KB885834)
http://www.microsoft.com/downloads/details.aspx?familyid=E9983AA2-2CEC -4B62-80D6-8E966A83A5D1&displaylang=en
Microsoft Windows Server 2003 Web Edition
-
Microsoft Security Update for Windows Server 2003 (KB885834)
http://www.microsoft.com/downloads/details.aspx?familyid=06EAF8E3-CCB7 -482B-8B68-340521150113&displaylang=en
Microsoft Windows 2000 Advanced Server SP3
-
Microsoft Security Update for Windows 2000 (KB885834)
http://www.microsoft.com/downloads/details.aspx?familyid=E9983AA2-2CEC -4B62-80D6-8E966A83A5D1&displaylang=en
Microsoft Windows 2000 Datacenter Server SP3
-
Microsoft Security Update for Windows 2000 (KB885834)
http://www.microsoft.com/downloads/details.aspx?familyid=E9983AA2-2CEC -4B62-80D6-8E966A83A5D1&displaylang=en
Microsoft Windows Server 2003 Enterprise Edition Itanium 0
-
Microsoft Security Update for Windows Server 2003 64-bit Edition (KB885834)
http://www.microsoft.com/downloads/details.aspx?familyid=EC25EC00-9C08 -4555-94C7-21D5A521FDB6&displaylang=en
Microsoft Windows 2000 Server SP3
-
Microsoft Security Update for Windows 2000 (KB885834)
http://www.microsoft.com/downloads/details.aspx?familyid=E9983AA2-2CEC -4B62-80D6-8E966A83A5D1&displaylang=en
Microsoft Windows NT Terminal Server 4.0 SP6
-
Microsoft Security Update for Windows NT Server 4.0, Terminal Server Edition (KB885834)
http://www.microsoft.com/downloads/details.aspx?familyid=F7B0934C-3049 -4B01-956A-B116F69A667E&displaylang=en
Microsoft Windows Server 2003 Standard Edition
-
Microsoft Security Update for Windows Server 2003 (KB885834)
http://www.microsoft.com/downloads/details.aspx?familyid=06EAF8E3-CCB7 -482B-8B68-340521150113&displaylang=en
Microsoft Windows NT Enterprise Server 4.0 SP6a
-
Microsoft Security Update for Windows NT Server 4.0 (KB885834)
http://www.microsoft.com/downloads/details.aspx?familyid=817FDC2D-AEE2 -4FAF-908B-197B65A471F2&displaylang=en
Microsoft Windows 2000 Server SP4
-
Microsoft Security Update for Windows 2000 (KB885834)
http://www.microsoft.com/downloads/details.aspx?familyid=E9983AA2-2CEC -4B62-80D6-8E966A83A5D1&displaylang=en
Microsoft Windows Server 2003 Datacenter Edition Itanium 0
-
Microsoft Security Update for Windows Server 2003 64-bit Edition (KB885834)
http://www.microsoft.com/downloads/details.aspx?familyid=EC25EC00-9C08 -4555-94C7-21D5A521FDB6&displaylang=en
References
Microsoft Windows License Logging Service Buffer Overflow Vulnerability
References:
References:
- LLSSRV: Clarification and correction of information on a public vulnerability. (IMMUNITY, INC.)
- Microsoft Security Bulletin MS05-010 (Microsoft)
- Windows 2000 Service Pack 4 does not update the Netserv.inf file when creating a (Microsoft)
- LLSSRV Redux (Dave Aitel
)