Microsoft Windows MSRPC SVCCTL Service Enumeration Vulnerability
BID:14177
Info
Microsoft Windows MSRPC SVCCTL Service Enumeration Vulnerability
| Bugtraq ID: | 14177 |
| Class: | Design Error |
| CVE: |
CVE-2005-2150 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 07 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Discovery is credited to Jean-Baptiste Marchand and Herv Schauer Consultants team. |
| Vulnerable: |
Microsoft Windows NT Workstation 4.0 SP6a Microsoft Windows NT Workstation 4.0 SP6 Microsoft Windows NT Workstation 4.0 SP5 Microsoft Windows NT Workstation 4.0 SP4 Microsoft Windows NT Workstation 4.0 SP3 Microsoft Windows NT Workstation 4.0 SP2 Microsoft Windows NT Workstation 4.0 SP1 Microsoft Windows NT Workstation 4.0 Microsoft Windows NT Terminal Server 4.0 SP6a Microsoft Windows NT Terminal Server 4.0 SP6 Microsoft Windows NT Terminal Server 4.0 SP5 Microsoft Windows NT Terminal Server 4.0 SP4 Microsoft Windows NT Terminal Server 4.0 SP3 Microsoft Windows NT Terminal Server 4.0 SP2 Microsoft Windows NT Terminal Server 4.0 SP1 Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6 Microsoft Windows NT Enterprise Server 4.0 SP5 Microsoft Windows NT Enterprise Server 4.0 SP4 Microsoft Windows NT Enterprise Server 4.0 SP3 Microsoft Windows NT Enterprise Server 4.0 SP2 Microsoft Windows NT Enterprise Server 4.0 SP1 Microsoft Windows NT Enterprise Server 4.0 Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Discussion
Microsoft Windows MSRPC SVCCTL Service Enumeration Vulnerability
Microsoft Windows is affected by a vulnerability that can allow anonymous remote attackers to enumerate installed or running services on an affected computer.
This issue may be exploited using hardcoded named pipes allowed for NULL sessions combined with svcctl interface and Microsoft Remote Procedure Call framework (MSRPC).
Microsoft Windows is affected by a vulnerability that can allow anonymous remote attackers to enumerate installed or running services on an affected computer.
This issue may be exploited using hardcoded named pipes allowed for NULL sessions combined with svcctl interface and Microsoft Remote Procedure Call framework (MSRPC).
Exploit / POC
Microsoft Windows MSRPC SVCCTL Service Enumeration Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Windows MSRPC SVCCTL Service Enumeration Vulnerability
Solution:
Microsoft has released various knowledge base articles to address issues in Windows 2000. Please see the articles in Web references for more information. Update Rollup 1 for Windows 2000 SP4 is available as a fix for Windows 2000 Service Pack 4.
Microsoft Windows 2000 Advanced Server SP4
Microsoft Windows 2000 Datacenter Server SP4
Microsoft Windows 2000 Server SP4
Microsoft Windows 2000 Professional SP4
Solution:
Microsoft has released various knowledge base articles to address issues in Windows 2000. Please see the articles in Web references for more information. Update Rollup 1 for Windows 2000 SP4 is available as a fix for Windows 2000 Service Pack 4.
Microsoft Windows 2000 Advanced Server SP4
-
Microsoft Update Rollup 1 for Windows 2000 SP4
http://www.microsoft.com/downloads/details.aspx?amp;displaylang=en&fam ilyid=B54730CF-8850-4531-B52B-BF28B324C662&displaylang=en
Microsoft Windows 2000 Datacenter Server SP4
-
Microsoft Update Rollup 1 for Windows 2000 SP4
http://www.microsoft.com/downloads/details.aspx?amp;displaylang=en&fam ilyid=B54730CF-8850-4531-B52B-BF28B324C662&displaylang=en
Microsoft Windows 2000 Server SP4
-
Microsoft Update Rollup 1 for Windows 2000 SP4
http://www.microsoft.com/downloads/details.aspx?amp;displaylang=en&fam ilyid=B54730CF-8850-4531-B52B-BF28B324C662&displaylang=en
Microsoft Windows 2000 Professional SP4
-
Microsoft Update Rollup 1 for Windows 2000 SP4
http://www.microsoft.com/downloads/details.aspx?amp;displaylang=en&fam ilyid=B54730CF-8850-4531-B52B-BF28B324C662&displaylang=en
References
Microsoft Windows MSRPC SVCCTL Service Enumeration Vulnerability
References:
References:
- Knowledge Base Article - 891861 (Microsoft)
- Knowledge Base Article - 900345 (Microsoft)
- NULL sessions vulnerabilities using alternate named pipes (Jean-Baptiste Marchand
)