Microsoft Windows NT/2000 NetBIOS Release Vulnerability
BID:1515
Info
Microsoft Windows NT/2000 NetBIOS Release Vulnerability
| Bugtraq ID: | 1515 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | Yes |
| Published: | Jul 27 2000 12:00AM |
| Updated: | Jul 27 2000 12:00AM |
| Credit: | Discovered by Sir Dystic <[email protected]> and publicized in a Microsoft Security Bulletin (MS00-047) on July 27, 2000. |
| Vulnerable: |
Microsoft Windows NT Workstation 4.0 SP6a Microsoft Windows NT Workstation 4.0 SP6 Microsoft Windows NT Workstation 4.0 SP5 Microsoft Windows NT Workstation 4.0 SP4 Microsoft Windows NT Workstation 4.0 SP3 Microsoft Windows NT Workstation 4.0 SP2 Microsoft Windows NT Workstation 4.0 SP1 Microsoft Windows NT Workstation 4.0 Microsoft Windows NT Terminal Server 4.0 SP6 Microsoft Windows NT Terminal Server 4.0 SP5 Microsoft Windows NT Terminal Server 4.0 SP4 Microsoft Windows NT Terminal Server 4.0 SP3 Microsoft Windows NT Terminal Server 4.0 SP2 Microsoft Windows NT Terminal Server 4.0 SP1 Microsoft Windows NT Terminal Server 4.0 alpha Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6 Microsoft Windows NT Enterprise Server 4.0 SP5 Microsoft Windows NT Enterprise Server 4.0 SP4 Microsoft Windows NT Enterprise Server 4.0 SP3 Microsoft Windows NT Enterprise Server 4.0 SP2 Microsoft Windows NT Enterprise Server 4.0 SP1 Microsoft Windows NT Enterprise Server 4.0 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Discussion
Microsoft Windows NT/2000 NetBIOS Release Vulnerability
An attacker can send the NetBIOS name service in a machine a NetBIOS Release message. That forces a receiving machine to place its name in conflict so that it will no longer be able to use it. This is the correct protocol behavior. MS's fix is to have a registry key that disables the NetBIOS name service from paying attention to these messages.
An attacker can send the NetBIOS name service in a machine a NetBIOS Release message. That forces a receiving machine to place its name in conflict so that it will no longer be able to use it. This is the correct protocol behavior. MS's fix is to have a registry key that disables the NetBIOS name service from paying attention to these messages.
Exploit / POC
Microsoft Windows NT/2000 NetBIOS Release Vulnerability
Sir Dystic <[email protected]> has provided the following exploit:
Source - nbname.cpp
Binary - nbname.exe
Sir Dystic <[email protected]> has provided the following exploit:
Source - nbname.cpp
Binary - nbname.exe
Solution / Fix
Microsoft Windows NT/2000 NetBIOS Release Vulnerability
Solution:
Microsoft has released the following patch which eliminates this vulnerability:
Microsoft Windows NT Enterprise Server 4.0
Microsoft Windows NT Terminal Server 4.0
Microsoft Windows NT Workstation 4.0 SP6a
Microsoft Windows NT Enterprise Server 4.0 SP3
Microsoft Windows NT Workstation 4.0 SP5
Microsoft Windows NT Enterprise Server 4.0 SP4
Microsoft Windows NT Workstation 4.0 SP2
Microsoft Windows NT Enterprise Server 4.0 SP5
Microsoft Windows NT Workstation 4.0 SP4
Microsoft Windows NT Terminal Server 4.0 SP2
Microsoft Windows NT Server 4.0 SP6a
Microsoft Windows NT Terminal Server 4.0 SP4
Microsoft Windows NT Enterprise Server 4.0 SP1
Microsoft Windows 2000 Professional
Microsoft Windows NT Terminal Server 4.0 SP1
Microsoft Windows NT Enterprise Server 4.0 SP2
Microsoft Windows NT Server 4.0 SP3
Microsoft Windows NT Terminal Server 4.0 SP3
Microsoft Windows NT Workstation 4.0 SP6
Microsoft Windows NT Server 4.0 SP1
Microsoft Windows NT Workstation 4.0
Microsoft Windows NT Enterprise Server 4.0 SP6
Microsoft Windows NT Server 4.0
Microsoft Windows NT Terminal Server 4.0 SP6
Microsoft Windows NT Workstation 4.0 SP3
Microsoft Windows NT Enterprise Server 4.0 SP6a
Microsoft Windows NT Server 4.0 SP6
Microsoft Windows NT Server 4.0 SP5
Microsoft Windows NT Server 4.0 SP2
Microsoft Windows NT Terminal Server 4.0 SP5
Microsoft Windows NT Workstation 4.0 SP1
Microsoft Windows 2000 Advanced Server
Microsoft Windows NT Server 4.0 SP4
Microsoft Windows 2000 Server
Solution:
Microsoft has released the following patch which eliminates this vulnerability:
Microsoft Windows NT Enterprise Server 4.0
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Terminal Server 4.0
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24516
Microsoft Windows NT Workstation 4.0 SP6a
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Enterprise Server 4.0 SP3
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Workstation 4.0 SP5
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Enterprise Server 4.0 SP4
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Workstation 4.0 SP2
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Enterprise Server 4.0 SP5
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Workstation 4.0 SP4
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Terminal Server 4.0 SP2
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24516
Microsoft Windows NT Server 4.0 SP6a
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Terminal Server 4.0 SP4
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24516
Microsoft Windows NT Enterprise Server 4.0 SP1
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows 2000 Professional
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=23370
Microsoft Windows NT Terminal Server 4.0 SP1
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24516
Microsoft Windows NT Enterprise Server 4.0 SP2
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Server 4.0 SP3
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Terminal Server 4.0 SP3
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24516
Microsoft Windows NT Workstation 4.0 SP6
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Server 4.0 SP1
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Workstation 4.0
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Enterprise Server 4.0 SP6
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Server 4.0
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Terminal Server 4.0 SP6
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24516
Microsoft Windows NT Workstation 4.0 SP3
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Enterprise Server 4.0 SP6a
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Server 4.0 SP6
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Server 4.0 SP5
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Server 4.0 SP2
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows NT Terminal Server 4.0 SP5
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24516
Microsoft Windows NT Workstation 4.0 SP1
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows 2000 Advanced Server
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=23370
Microsoft Windows NT Server 4.0 SP4
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=22138
Microsoft Windows 2000 Server
-
Microsoft Q269239
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=23370
References
Microsoft Windows NT/2000 NetBIOS Release Vulnerability
References:
References:
- Frequently Asked Questions: Microsoft Security Bulletin (MS00-047) (Microsoft)
- NBName (Sir Dystic)
- Q269239: NetBIOS Vulnerability May Cause Duplicate Name on the Network Conflicts (Microsoft)