Microsoft Windows NT 4.0 / 2000 LPC Zone Memory Depletion DoS Vulnerability
BID:1745
Info
Microsoft Windows NT 4.0 / 2000 LPC Zone Memory Depletion DoS Vulnerability
| Bugtraq ID: | 1745 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Oct 03 2000 12:00AM |
| Updated: | Oct 03 2000 12:00AM |
| Credit: | Discovered by BindView's Razor Team <[email protected]> and publicized in a Microsoft Security Bulletin (MS00-070) on October 3, 2000. |
| Vulnerable: |
Microsoft Windows NT Workstation 4.0 SP6a Microsoft Windows NT Workstation 4.0 SP6 Microsoft Windows NT Workstation 4.0 SP5 Microsoft Windows NT Workstation 4.0 SP4 Microsoft Windows NT Workstation 4.0 SP3 Microsoft Windows NT Workstation 4.0 SP2 Microsoft Windows NT Workstation 4.0 SP1 Microsoft Windows NT Workstation 4.0 Microsoft Windows NT Terminal Server 4.0 SP6 Microsoft Windows NT Terminal Server 4.0 SP5 Microsoft Windows NT Terminal Server 4.0 SP4 Microsoft Windows NT Terminal Server 4.0 SP3 Microsoft Windows NT Terminal Server 4.0 SP2 Microsoft Windows NT Terminal Server 4.0 SP1 Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6 Microsoft Windows NT Enterprise Server 4.0 SP5 Microsoft Windows NT Enterprise Server 4.0 SP4 Microsoft Windows NT Enterprise Server 4.0 SP3 Microsoft Windows NT Enterprise Server 4.0 SP2 Microsoft Windows NT Enterprise Server 4.0 SP1 Microsoft Windows NT Enterprise Server 4.0 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Exploit / POC
Microsoft Windows NT 4.0 / 2000 LPC Zone Memory Depletion DoS Vulnerability
Bindview's Razor Team has provided a proof-of-concept tool (porttool.zip) to demonstrate the vulnerabilities that exist in Microsoft NT's implementation of LPC.
start porttool -s6 \BaseNamedObjects\Foo
porttool -c6 \BaseNamedObject\Foo
Bindview's Razor Team has provided a proof-of-concept tool (porttool.zip) to demonstrate the vulnerabilities that exist in Microsoft NT's implementation of LPC.
start porttool -s6 \BaseNamedObjects\Foo
porttool -c6 \BaseNamedObject\Foo
Solution / Fix
Microsoft Windows NT 4.0 / 2000 LPC Zone Memory Depletion DoS Vulnerability
Solution:
Microsoft has released the following patches which eliminate this vulnerability including the other LPC vulnerabilities discussed in the Microsoft Security Bulletin (MS00-070):
Microsoft Windows 2000 Advanced Server SP1
Microsoft Windows 2000 Datacenter Server
Microsoft Windows NT Workstation 4.0 SP6a
Microsoft Windows 2000 Datacenter Server SP1
Microsoft Windows NT Server 4.0 SP6a
Microsoft Windows 2000 Professional
Microsoft Windows 2000 Professional SP1
Microsoft Windows NT Enterprise Server 4.0 SP6a
Microsoft Windows 2000 Server SP1
Microsoft Windows 2000 Advanced Server
Microsoft Windows 2000 Server
Solution:
Microsoft has released the following patches which eliminate this vulnerability including the other LPC vulnerabilities discussed in the Microsoft Security Bulletin (MS00-070):
Microsoft Windows 2000 Advanced Server SP1
-
Microsoft Q266433
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24649
Microsoft Windows 2000 Datacenter Server
-
Microsoft Q266433
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24649
Microsoft Windows NT Workstation 4.0 SP6a
-
Microsoft Q266433
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24650
Microsoft Windows 2000 Datacenter Server SP1
-
Microsoft Q266433
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24649
Microsoft Windows NT Server 4.0 SP6a
-
Microsoft Q266433
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24650
Microsoft Windows 2000 Professional
-
Microsoft Q266433
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24649
Microsoft Windows 2000 Professional SP1
-
Microsoft Q266433
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24649
Microsoft Windows NT Enterprise Server 4.0 SP6a
-
Microsoft Q266433
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24650
Microsoft Windows 2000 Server SP1
-
Microsoft Q266433
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24649
Microsoft Windows 2000 Advanced Server
-
Microsoft Q266433
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24649
Microsoft Windows 2000 Server
-
Microsoft Q266433
http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24649