Microsoft Windows Wireless Zero Configuration Service Information Disclosure Vulnerability
BID:15008
Info
Microsoft Windows Wireless Zero Configuration Service Information Disclosure Vulnerability
| Bugtraq ID: | 15008 |
| Class: | Design Error |
| CVE: | |
| Remote: | Unknown |
| Local: | Yes |
| Published: | Oct 04 2005 12:00AM |
| Updated: | Oct 04 2005 12:00AM |
| Credit: | Discovery is credited to donctl <[email protected]>. |
| Vulnerable: |
Microsoft Windows XP Tablet PC Edition SP2 Microsoft Windows XP Professional SP2 Microsoft Windows XP Media Center Edition SP2 Microsoft Windows XP Home SP2 |
| Not Vulnerable: | |
Discussion
Microsoft Windows Wireless Zero Configuration Service Information Disclosure Vulnerability
WZCSVC is affected by an information disclosure vulnerability.
Reportedly, the Pairwise Master Key (PMK) of the Wi-Fi Protected Access (WPA) preshared key authentication and the WEP keys of the interface may be obtained by a local unauthorized attacker.
A successful attack can allow an attacker to obtain the keys and subsequently gain unauthorized access to a device. This attack would likely present itself in a multi-user environment with restricted or temporary wireless access such as an Internet cafe, where an attacker could return at a later time and gain unauthorized access.
Microsoft Windows XP SP2 was reported to be vulnerable, however, it is possible that other versions are affected as well.
WZCSVC is affected by an information disclosure vulnerability.
Reportedly, the Pairwise Master Key (PMK) of the Wi-Fi Protected Access (WPA) preshared key authentication and the WEP keys of the interface may be obtained by a local unauthorized attacker.
A successful attack can allow an attacker to obtain the keys and subsequently gain unauthorized access to a device. This attack would likely present itself in a multi-user environment with restricted or temporary wireless access such as an Internet cafe, where an attacker could return at a later time and gain unauthorized access.
Microsoft Windows XP SP2 was reported to be vulnerable, however, it is possible that other versions are affected as well.
Exploit / POC
Microsoft Windows Wireless Zero Configuration Service Information Disclosure Vulnerability
An exploit is not required.
The following proof of concept is available:
An exploit is not required.
The following proof of concept is available:
Solution / Fix
Microsoft Windows Wireless Zero Configuration Service Information Disclosure Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Windows Wireless Zero Configuration Service Information Disclosure Vulnerability
References:
References:
- Technet Security (Microsoft)
- Advisory: WZCS vulnerabilities (donctl
)