Microsoft ActiveSync Network Synchronization Multiple Vulnerabilities
BID:14457
Info
Microsoft ActiveSync Network Synchronization Multiple Vulnerabilities
| Bugtraq ID: | 14457 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 02 2005 12:00AM |
| Updated: | Aug 02 2005 12:00AM |
| Credit: | Natalia Melnikova, and Seth Fogie are credited with the discovery of these vulnerabilities. |
| Vulnerable: |
Microsoft ActiveSync 3.7.1 Microsoft ActiveSync 3.8 |
| Not Vulnerable: | |
Discussion
Microsoft ActiveSync Network Synchronization Multiple Vulnerabilities
Several specific issues have been identified with the network synchronization protocol used by Microsoft ActiveSync.
The first issue is the use of cleartext communications for all network traffic.
The second issue is the lack of password authentication.
The third issue is an information disclosure issue when attempting to initiate network synchronization.
The last issue is a denial of service vulnerability.
These issues combine to allow remote attackers to gain access to potentially sensitive information, aiding them in further attacks. Attackers may also alter or destroy data by simulating the synchronization protocol, or crash the ActiveSync service.
Several specific issues have been identified with the network synchronization protocol used by Microsoft ActiveSync.
The first issue is the use of cleartext communications for all network traffic.
The second issue is the lack of password authentication.
The third issue is an information disclosure issue when attempting to initiate network synchronization.
The last issue is a denial of service vulnerability.
These issues combine to allow remote attackers to gain access to potentially sensitive information, aiding them in further attacks. Attackers may also alter or destroy data by simulating the synchronization protocol, or crash the ActiveSync service.
Exploit / POC
Microsoft ActiveSync Network Synchronization Multiple Vulnerabilities
An exploit is not required.
An exploit is not required.
Solution / Fix
Microsoft ActiveSync Network Synchronization Multiple Vulnerabilities
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft ActiveSync Network Synchronization Multiple Vulnerabilities
References:
References:
- ActiveSync 3.5 (Microsoft)
- Microsoft ActiveSync (Securitylab.ru)
- Microsoft ActiveSync information leak and spoofing (3APA3A <[email protected]>)