Microsoft Agent agentdpv.dll ActiveX Control Malformed URL Stack Buffer Overflow Vulnerability
BID:25566
Info
Microsoft Agent agentdpv.dll ActiveX Control Malformed URL Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 25566 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2007-3040 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 11 2007 12:00AM |
| Updated: | Apr 21 2009 01:26PM |
| Credit: | The vulnerability research team of Assurent Secure Technologies, Yamata Li of Palo Alto Networks and Jardel Weyrich are credited with the discovery of this vulnerability. |
| Vulnerable: |
Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server HP Storage Management Appliance III HP Storage Management Appliance II HP Storage Management Appliance I HP Storage Management Appliance 2.1 |
| Not Vulnerable: | |
Discussion
Microsoft Agent agentdpv.dll ActiveX Control Malformed URL Stack Buffer Overflow Vulnerability
Microsoft Agent (agentsvr.exe) is prone to a stack-based buffer-overflow vulnerability because the application fails to adequately bounds-check user-supplied data.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial-of-service conditions.
Microsoft Agent (agentsvr.exe) is prone to a stack-based buffer-overflow vulnerability because the application fails to adequately bounds-check user-supplied data.
Successfully exploiting this issue allows remote attackers to execute arbitrary code in the context of the currently logged-in user. Failed exploit attempts will likely result in denial-of-service conditions.
Exploit / POC
Microsoft Agent agentdpv.dll ActiveX Control Malformed URL Stack Buffer Overflow Vulnerability
The following exploit code is available to members of the Immunity Partners Program:
https://www.immunityinc.com/downloads/immpartners/ms07_051.tgz
The following proof-of-concept code is available:
The following exploit code is available to members of the Immunity Partners Program:
https://www.immunityinc.com/downloads/immpartners/ms07_051.tgz
The following proof-of-concept code is available:
Solution / Fix
Microsoft Agent agentdpv.dll ActiveX Control Malformed URL Stack Buffer Overflow Vulnerability
Solution:
Microsoft has released security advisory MS07-051 to address this issue in supported versions of affected applications. Please see the referenced advisory for more information.
Microsoft Windows 2000 Advanced Server SP4
Microsoft Windows 2000 Server SP4
Microsoft Windows 2000 Professional SP4
Microsoft Windows 2000 Datacenter Server SP4
Solution:
Microsoft has released security advisory MS07-051 to address this issue in supported versions of affected applications. Please see the referenced advisory for more information.
Microsoft Windows 2000 Advanced Server SP4
-
Microsoft Security Update for Windows 2000 (KB938827)
http://www.microsoft.com/downloads/details.aspx?FamilyId=7cd248ed-d154 -4dce-89ef-ceefd2700965&displaylang=en
Microsoft Windows 2000 Server SP4
-
Microsoft Security Update for Windows 2000 (KB938827)
http://www.microsoft.com/downloads/details.aspx?FamilyId=7cd248ed-d154 -4dce-89ef-ceefd2700965&displaylang=en
Microsoft Windows 2000 Professional SP4
-
Microsoft Security Update for Windows 2000 (KB938827)
http://www.microsoft.com/downloads/details.aspx?FamilyId=7cd248ed-d154 -4dce-89ef-ceefd2700965&displaylang=en
Microsoft Windows 2000 Datacenter Server SP4
-
Microsoft Security Update for Windows 2000 (KB938827)
http://www.microsoft.com/downloads/details.aspx?FamilyId=7cd248ed-d154 -4dce-89ef-ceefd2700965&displaylang=en
References
Microsoft Agent agentdpv.dll ActiveX Control Malformed URL Stack Buffer Overflow Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- Microsoft Knowledge Base Article 240797 (Microsoft)
- Assurent VR - Microsoft Agent Crafted URL Stack Buffer Overflow ([email protected])
- Microsoft Windows 2000 Agent RL Canonicalizing Buffer Overflow Vulnerability ([email protected])
- Microsoft Security Bulletin MS07-051 (Microsoft)
- Microsoft Windows 2000 Agent URL Canonicalizing Buffer Overflow Vulnerability (iDefense Labs)
- Vulnerability Note VU#716872 (US-CERT)