Microsoft Windows MSRPC Eventlog Information Disclosure Vulnerability
BID:14178
Info
Microsoft Windows MSRPC Eventlog Information Disclosure Vulnerability
| Bugtraq ID: | 14178 |
| Class: | Design Error |
| CVE: |
CVE-2005-2150 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 07 2005 12:00AM |
| Updated: | Jul 12 2009 04:06PM |
| Credit: | Discovery is credited to Jean-Baptiste Marchand and Herv Schauer Consultants team. |
| Vulnerable: |
Microsoft Windows NT Workstation 4.0 SP6a Microsoft Windows NT Workstation 4.0 SP6 Microsoft Windows NT Workstation 4.0 SP5 Microsoft Windows NT Workstation 4.0 SP4 Microsoft Windows NT Workstation 4.0 SP3 Microsoft Windows NT Workstation 4.0 SP2 Microsoft Windows NT Workstation 4.0 SP1 Microsoft Windows NT Workstation 4.0 Microsoft Windows NT Terminal Server 4.0 SP6a Microsoft Windows NT Terminal Server 4.0 SP6 Microsoft Windows NT Terminal Server 4.0 SP5 Microsoft Windows NT Terminal Server 4.0 SP4 Microsoft Windows NT Terminal Server 4.0 SP3 Microsoft Windows NT Terminal Server 4.0 SP2 Microsoft Windows NT Terminal Server 4.0 SP1 Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6 Microsoft Windows NT Enterprise Server 4.0 SP5 Microsoft Windows NT Enterprise Server 4.0 SP4 Microsoft Windows NT Enterprise Server 4.0 SP3 Microsoft Windows NT Enterprise Server 4.0 SP2 Microsoft Windows NT Enterprise Server 4.0 SP1 Microsoft Windows NT Enterprise Server 4.0 Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server Microsoft .NET Framework 1.0 |
| Not Vulnerable: | |
Discussion
Microsoft Windows MSRPC Eventlog Information Disclosure Vulnerability
Microsoft Windows allows remote attackers to disclose the application or system eventlog of an affected computer. This issue may be exploited using hardcoded named pipes allowed for NULL sessions combined with eventlog interface and Microsoft Remote Procedure Call framework (MSRPC).
Information gathered through the exploitation of this issue may aid in other attacks.
Microsoft Windows allows remote attackers to disclose the application or system eventlog of an affected computer. This issue may be exploited using hardcoded named pipes allowed for NULL sessions combined with eventlog interface and Microsoft Remote Procedure Call framework (MSRPC).
Information gathered through the exploitation of this issue may aid in other attacks.
Exploit / POC
Microsoft Windows MSRPC Eventlog Information Disclosure Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Windows MSRPC Eventlog Information Disclosure Vulnerability
Solution:
Microsoft has released various knowledge base articles to address issues in Windows 2000. Please see the articles in Web references for more information. Update Rollup 1 for Windows 2000 SP4 is available as a fix for Windows 2000 Service Pack 4.
Microsoft Windows 2000 Advanced Server SP4
Microsoft Windows 2000 Datacenter Server SP4
Microsoft Windows 2000 Server SP4
Microsoft Windows 2000 Professional SP4
Solution:
Microsoft has released various knowledge base articles to address issues in Windows 2000. Please see the articles in Web references for more information. Update Rollup 1 for Windows 2000 SP4 is available as a fix for Windows 2000 Service Pack 4.
Microsoft Windows 2000 Advanced Server SP4
-
Microsoft Update Rollup 1 for Windows 2000 SP4
http://www.microsoft.com/downloads/details.aspx?amp;displaylang=en&fam ilyid=B54730CF-8850-4531-B52B-BF28B324C662&displaylang=en
Microsoft Windows 2000 Datacenter Server SP4
-
Microsoft Update Rollup 1 for Windows 2000 SP4
http://www.microsoft.com/downloads/details.aspx?amp;displaylang=en&fam ilyid=B54730CF-8850-4531-B52B-BF28B324C662&displaylang=en
Microsoft Windows 2000 Server SP4
-
Microsoft Update Rollup 1 for Windows 2000 SP4
http://www.microsoft.com/downloads/details.aspx?amp;displaylang=en&fam ilyid=B54730CF-8850-4531-B52B-BF28B324C662&displaylang=en
Microsoft Windows 2000 Professional SP4
-
Microsoft Update Rollup 1 for Windows 2000 SP4
http://www.microsoft.com/downloads/details.aspx?amp;displaylang=en&fam ilyid=B54730CF-8850-4531-B52B-BF28B324C662&displaylang=en
References
Microsoft Windows MSRPC Eventlog Information Disclosure Vulnerability
References:
References:
- Knowledge Base Article - 891861 (Microsoft)
- Knowledge Base Article - 900345 (Microsoft)
- NULL sessions vulnerabilities using alternate named pipes (Jean-Baptiste Marchand
)