Microsoft Management Console Zone Bypass Vulnerability
BID:19417
CVE-2006-3643 |Info
Microsoft Management Console Zone Bypass Vulnerability
| Bugtraq ID: | 19417 |
| Class: | Access Validation Error |
| CVE: |
CVE-2006-3643 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 08 2006 12:00AM |
| Updated: | Jun 27 2007 03:28AM |
| Credit: | Yorick Koster of ITsec Security Services, HD Moore, and Tom Gilder are each respectively credited with reporting this vulnerability to the vendor. |
| Vulnerable: |
Nortel Networks Self-Service Speech Server 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service MPS 500 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service MPS 100 0 Nortel Networks MCS5100 - Sun Platform 0 Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Discussion
Microsoft Management Console Zone Bypass Vulnerability
Microsoft Management Console (MMC) is prone to a cross-zone scripting vulnerability because the operating system fails to properly restrict access to MMC components, allowing the MMC files to be referenced from the Internet Zone in some cases.
Exploiting this vulnerability could let an attacker execute arbitrary code, completely compromising the computer.
Microsoft Management Console (MMC) is prone to a cross-zone scripting vulnerability because the operating system fails to properly restrict access to MMC components, allowing the MMC files to be referenced from the Internet Zone in some cases.
Exploiting this vulnerability could let an attacker execute arbitrary code, completely compromising the computer.
Exploit / POC
Microsoft Management Console Zone Bypass Vulnerability
This issue is currently being exploited in the wild.
A proof-of-concept demonstration is available from an external source. Please see the references for more information.
NOTE: Symantec has not verified the integrity of this proof of concept; users are advised to use caution when running code from external sites.
UPDATE (May 15, 2007): This issue is being exploited by the MPack hacker tool. Please see the references for more information.
This issue is currently being exploited in the wild.
A proof-of-concept demonstration is available from an external source. Please see the references for more information.
NOTE: Symantec has not verified the integrity of this proof of concept; users are advised to use caution when running code from external sites.
UPDATE (May 15, 2007): This issue is being exploited by the MPack hacker tool. Please see the references for more information.
Solution / Fix
Microsoft Management Console Zone Bypass Vulnerability
Solution:
Microsoft has released a security bulletin to address this issue. Please see the references for details.
Solution:
Microsoft has released a security bulletin to address this issue. Please see the references for details.
References
Microsoft Management Console Zone Bypass Vulnerability
References:
References:
- MS06-044 - Internet Explorer 5.x (Browser Fun)
- BULLETIN - 2006007224 ] NORTEL RESPONSE TO MICROSOFT SECURITY BULLETIN MS06-044 (Nortel)
- Microsoft Security Bulletin MS06-044 (Microsoft)
- MPack Uncovered (pdf document) (PandaLabs)
- Proof-of-concept Demonstration (Browser Fun)