Microsoft Windows NT 4.0 Networking Mutex DoS Vulnerability
BID:2303
Info
Microsoft Windows NT 4.0 Networking Mutex DoS Vulnerability
| Bugtraq ID: | 2303 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 24 2001 12:00AM |
| Updated: | Jan 24 2001 12:00AM |
| Credit: | Discovered by Arne Vidstrom and posted in a Microsoft Security Bulletin (MS01-003) on Jan 24, 2001 |
| Vulnerable: |
Microsoft Windows NT Workstation 4.0 SP6a Microsoft Windows NT Workstation 4.0 SP6 Microsoft Windows NT Workstation 4.0 SP5 Microsoft Windows NT Workstation 4.0 SP4 Microsoft Windows NT Workstation 4.0 SP3 Microsoft Windows NT Workstation 4.0 SP2 Microsoft Windows NT Workstation 4.0 SP1 Microsoft Windows NT Workstation 4.0 Microsoft Windows NT Terminal Server 4.0 SP6 Microsoft Windows NT Terminal Server 4.0 SP5 Microsoft Windows NT Terminal Server 4.0 SP4 Microsoft Windows NT Terminal Server 4.0 SP3 Microsoft Windows NT Terminal Server 4.0 SP2 Microsoft Windows NT Terminal Server 4.0 SP1 Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6 Microsoft Windows NT Enterprise Server 4.0 SP5 Microsoft Windows NT Enterprise Server 4.0 SP4 Microsoft Windows NT Enterprise Server 4.0 SP3 Microsoft Windows NT Enterprise Server 4.0 SP2 Microsoft Windows NT Enterprise Server 4.0 SP1 Microsoft Windows NT Enterprise Server 4.0 |
| Not Vulnerable: | |
Discussion
Microsoft Windows NT 4.0 Networking Mutex DoS Vulnerability
Microsoft Windows NT 4.0 is subject to a denial of service due to the implementation of incorrect permissions in a Mutex object. A local user could gain control of the Mutex on a networked machine and deny all network communication.
Microsoft Windows NT 4.0 is subject to a denial of service due to the implementation of incorrect permissions in a Mutex object. A local user could gain control of the Mutex on a networked machine and deny all network communication.
Exploit / POC
Microsoft Windows NT 4.0 Networking Mutex DoS Vulnerability
The following exploit has been provided by Arne Vidstrom <[email protected]>
The following exploit has been provided by Arne Vidstrom <[email protected]>
Solution / Fix
Microsoft Windows NT 4.0 Networking Mutex DoS Vulnerability
Solution:
Microsoft has release a patch which addresses this issue:
Microsoft Windows NT Terminal Server 4.0
Microsoft Windows NT Workstation 4.0 SP6a
Microsoft Windows NT Terminal Server 4.0 SP6
Microsoft Windows NT Enterprise Server 4.0 SP6a
Microsoft Windows NT Server 4.0 SP6a
Solution:
Microsoft has release a patch which addresses this issue:
Microsoft Windows NT Terminal Server 4.0
-
Microsoft Q279336
http://download.microsoft.com/download/winntsp/Patch/q279336/NT4/EN-US /Q279336i.EXE
Microsoft Windows NT Workstation 4.0 SP6a
-
Microsoft Q279336
http://download.microsoft.com/download/winntsp/Patch/q279336/NT4/EN-US /Q279336i.EXE
Microsoft Windows NT Terminal Server 4.0 SP6
-
Microsoft Q279336
http://www.microsoft.com/ntserver/terminalserver/downloads/critical/q2 79336/default.asp
Microsoft Windows NT Enterprise Server 4.0 SP6a
-
Microsoft Q279336
http://download.microsoft.com/download/winntsp/Patch/q279336/NT4/EN-US /Q279336i.EXE
Microsoft Windows NT Server 4.0 SP6a
References
Microsoft Windows NT 4.0 Networking Mutex DoS Vulnerability
References:
References: