Microsoft Windows Named Pipe Remote Information Disclosure Vulnerability
BID:12486
Info
Microsoft Windows Named Pipe Remote Information Disclosure Vulnerability
| Bugtraq ID: | 12486 |
| Class: | Access Validation Error |
| CVE: |
CVE-2005-0051 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 08 2005 12:00AM |
| Updated: | Jul 12 2009 10:06AM |
| Credit: | Jean-Baptiste Marchand is credited with the discovery of this issue. |
| Vulnerable: |
Microsoft Windows XP Tablet PC Edition SP2 Microsoft Windows XP Tablet PC Edition SP1 Microsoft Windows XP Tablet PC Edition Microsoft Windows XP Professional SP2 Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Media Center Edition SP2 Microsoft Windows XP Media Center Edition SP1 Microsoft Windows XP Media Center Edition Microsoft Windows XP Home SP2 Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows XP 64-bit Edition SP1 Microsoft Windows XP 64-bit Edition |
| Not Vulnerable: | |
Discussion
Microsoft Windows Named Pipe Remote Information Disclosure Vulnerability
A remote information disclosure vulnerability affects Microsoft Windows. This issue is due to a failure of the application to securely store potentially sensitive system information.
An attacker may leverage this issue to disclose the user names of all users connected to a network share, potentially facilitating further attacks against affected computers.
A remote information disclosure vulnerability affects Microsoft Windows. This issue is due to a failure of the application to securely store potentially sensitive system information.
An attacker may leverage this issue to disclose the user names of all users connected to a network share, potentially facilitating further attacks against affected computers.
Exploit / POC
Microsoft Windows Named Pipe Remote Information Disclosure Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Windows Named Pipe Remote Information Disclosure Vulnerability
Solution:
Microsoft has released updates to address this issue on supported platforms.
Microsoft Windows XP Media Center Edition SP1
Microsoft Windows XP Tablet PC Edition SP2
Microsoft Windows XP Media Center Edition SP2
Microsoft Windows XP Professional SP2
Microsoft Windows XP Home SP1
Microsoft Windows XP Tablet PC Edition SP1
Microsoft Windows XP Tablet PC Edition
Microsoft Windows XP Professional SP1
Microsoft Windows XP 64-bit Edition SP1
Microsoft Windows XP Home SP2
Solution:
Microsoft has released updates to address this issue on supported platforms.
Microsoft Windows XP Media Center Edition SP1
-
Microsoft Security Update for Windows XP (KB888302)
http://download.microsoft.com/download/e/b/8/eb8e1485-0e8e-4c52-b420-9 4e70f13cb0e/WindowsXP-KB888302-x86-ENU.exe
Microsoft Windows XP Tablet PC Edition SP2
-
Microsoft Security Update for Windows XP (KB888302)
http://download.microsoft.com/download/e/b/8/eb8e1485-0e8e-4c52-b420-9 4e70f13cb0e/WindowsXP-KB888302-x86-ENU.exe
Microsoft Windows XP Media Center Edition SP2
-
Microsoft Security Update for Windows XP (KB888302)
http://download.microsoft.com/download/e/b/8/eb8e1485-0e8e-4c52-b420-9 4e70f13cb0e/WindowsXP-KB888302-x86-ENU.exe
Microsoft Windows XP Professional SP2
-
Microsoft Security Update for Windows XP (KB888302)
http://download.microsoft.com/download/e/b/8/eb8e1485-0e8e-4c52-b420-9 4e70f13cb0e/WindowsXP-KB888302-x86-ENU.exe
Microsoft Windows XP Home SP1
-
Microsoft Security Update for Windows XP (KB888302)
http://download.microsoft.com/download/e/b/8/eb8e1485-0e8e-4c52-b420-9 4e70f13cb0e/WindowsXP-KB888302-x86-ENU.exe
Microsoft Windows XP Tablet PC Edition SP1
-
Microsoft Security Update for Windows XP (KB888302)
http://download.microsoft.com/download/e/b/8/eb8e1485-0e8e-4c52-b420-9 4e70f13cb0e/WindowsXP-KB888302-x86-ENU.exe
Microsoft Windows XP Tablet PC Edition
-
Microsoft Security Update for Windows XP (KB888302)
http://download.microsoft.com/download/e/b/8/eb8e1485-0e8e-4c52-b420-9 4e70f13cb0e/WindowsXP-KB888302-x86-ENU.exe
Microsoft Windows XP Professional SP1
-
Microsoft Security Update for Windows XP (KB888302)
http://download.microsoft.com/download/e/b/8/eb8e1485-0e8e-4c52-b420-9 4e70f13cb0e/WindowsXP-KB888302-x86-ENU.exe
Microsoft Windows XP 64-bit Edition SP1
-
Microsoft Security Update for Windows XP 64-bit Edition (KB888302)
http://download.microsoft.com/download/a/b/c/abc216b0-080d-4d55-ad76-e ddefd16b493/WindowsXP-KB888302-ia64-ENU.exe
Microsoft Windows XP Home SP2
-
Microsoft Security Update for Windows XP (KB888302)
http://download.microsoft.com/download/e/b/8/eb8e1485-0e8e-4c52-b420-9 4e70f13cb0e/WindowsXP-KB888302-x86-ENU.exe
References
Microsoft Windows Named Pipe Remote Information Disclosure Vulnerability
References:
References:
- Microsoft Security Bulletin MS05-007 (Microsoft)
- Windows XP Homepage (Microsoft)
- Some details about MS05-007 security bulletin (Jean-Baptiste Marchand
)