Microsoft Windows Media Server MDSAuth.DLL ActiveX Control Remote Code Execution Vulnerability
BID:23827
Info
Microsoft Windows Media Server MDSAuth.DLL ActiveX Control Remote Code Execution Vulnerability
| Bugtraq ID: | 23827 |
| Class: | Unknown |
| CVE: |
CVE-2007-2221 |
| Remote: | Yes |
| Local: | No |
| Published: | May 08 2007 12:00AM |
| Updated: | May 17 2007 09:38PM |
| Credit: | Cocoruder from Fortinet Security Research is credited with discovering this issue. |
| Vulnerable: |
Nortel Networks Contact Center Web Client Nortel Networks Contact Center Multimedia Nortel Networks Contact Center Manager Server 0 Nortel Networks Contact Center Manager Nortel Networks Contact Center Express Nortel Networks Contact Center Administration 0 Nortel Networks Contact Center - Symposium Agent 0 Nortel Networks Contact Center Nortel Networks Centrex IP Client Manager Nortel Networks CallPilot 703t Nortel Networks CallPilot 702t Nortel Networks CallPilot 201i Nortel Networks CallPilot 200i Nortel Networks CallPilot 1002rp Microsoft Windows XP Tablet PC Edition SP2 Microsoft Windows XP Professional x64 Edition SP2 Microsoft Windows XP Professional x64 Edition Microsoft Windows XP Professional SP2 Microsoft Windows XP Media Center Edition SP2 Microsoft Windows XP Home SP2 Microsoft Windows Vista x64 Edition 0 Microsoft Windows Vista Ultimate Microsoft Windows Vista Home Premium Microsoft Windows Vista Home Basic Microsoft Windows Vista Enterprise Microsoft Windows Vista Business Microsoft Windows Vista 0 Microsoft Windows Server 2003 x64 SP2 Microsoft Windows Server 2003 Web Edition SP2 Microsoft Windows Server 2003 Web Edition SP1 Microsoft Windows Server 2003 Web Edition Microsoft Windows Server 2003 Standard x64 Edition Microsoft Windows Server 2003 Standard Edition SP2 Microsoft Windows Server 2003 Standard Edition SP1 Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Itanium SP2 Microsoft Windows Server 2003 Itanium SP1 Microsoft Windows Server 2003 Itanium 0 Microsoft Windows Server 2003 Enterprise x64 Edition SP2 Microsoft Windows Server 2003 Enterprise x64 Edition Microsoft Windows Server 2003 Enterprise Edition Itanium SP1 Beta 1 Microsoft Windows Server 2003 Enterprise Edition Itanium SP1 Microsoft Windows Server 2003 Enterprise Edition Itanium 0 Microsoft Windows Server 2003 Enterprise Edition SP1 Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Datacenter x64 Edition SP2 Microsoft Windows Server 2003 Datacenter x64 Edition Microsoft Windows Server 2003 Datacenter Edition Itanium SP1 Beta 1 Microsoft Windows Server 2003 Datacenter Edition Itanium SP1 Microsoft Windows Server 2003 Datacenter Edition Itanium 0 Microsoft Windows Server 2003 Datacenter Edition SP1 Microsoft Windows Server 2003 SP2 Microsoft Windows Server 2003 SP1 Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional HP Storage Management Appliance 2.1 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server 0 Avaya Customer Interaction Express (CIE) User Interface 1.0 Avaya Customer Interaction Express (CIE) Server 1.0 Avaya CIE 1.0 |
| Not Vulnerable: | |
Discussion
Microsoft Windows Media Server MDSAuth.DLL ActiveX Control Remote Code Execution Vulnerability
The Microsoft Windows Media Server ActiveX control is prone to a remote code-execution vulnerability.
An attacker may exploit this issue by enticing victims into opening a maliciously crafted HTML document.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
The Microsoft Windows Media Server ActiveX control is prone to a remote code-execution vulnerability.
An attacker may exploit this issue by enticing victims into opening a maliciously crafted HTML document.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the application using the ActiveX control (typically Internet Explorer). Failed exploit attempts likely result in denial-of-service conditions.
Exploit / POC
Microsoft Windows Media Server MDSAuth.DLL ActiveX Control Remote Code Execution Vulnerability
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
Microsoft Windows Media Server MDSAuth.DLL ActiveX Control Remote Code Execution Vulnerability
Solution:
Microsoft has released fixes to address this issue. Please see the references for more information.
Solution:
Microsoft has released fixes to address this issue. Please see the references for more information.
References
Microsoft Windows Media Server MDSAuth.DLL ActiveX Control Remote Code Execution Vulnerability
References:
References:
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Microsoft Security Bulletin MS07-027 (Microsoft)
- Microsoft Windows Homepage (Microsoft)
- 2007007972: Nortel Response to Microsoft Security Bulletin MS07-027 (Nortel Networks)
- ASA-2007-182 MS07-027 Cumulative Security Update for Internet Explorer (931768) (Avaya)
- Vulnerability Note VU#500753 (US-CERT)