Microsoft Windows Recursive DNS Spoofing Vulnerability
BID:25919
Info
Microsoft Windows Recursive DNS Spoofing Vulnerability
| Bugtraq ID: | 25919 |
| Class: | Design Error |
| CVE: |
CVE-2007-3898 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 13 2007 12:00AM |
| Updated: | Nov 20 2007 06:54PM |
| Credit: | Alla Berzroutchko of Scanit and Amit Klein of Trusteer are credited with the discovery of this vulnerability |
| Vulnerable: |
Microsoft Windows Server 2003 Web Edition SP2 Microsoft Windows Server 2003 Web Edition SP1 Microsoft Windows Server 2003 Web Edition Microsoft Windows Server 2003 Standard Edition SP2 Microsoft Windows Server 2003 Standard Edition SP1 Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Itanium SP2 Microsoft Windows Server 2003 Itanium SP1 Microsoft Windows Server 2003 Itanium 0 Microsoft Windows Server 2003 Enterprise x64 Edition SP2 Microsoft Windows Server 2003 Enterprise x64 Edition Microsoft Windows Server 2003 Enterprise Edition Itanium SP1 Microsoft Windows Server 2003 Enterprise Edition SP1 Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Datacenter Edition SP1 Microsoft Windows Server 2003 Datacenter Edition Microsoft Windows Server 2003 SP2 Microsoft Windows Server 2003 SP1 Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 0 |
| Not Vulnerable: | |
Discussion
Microsoft Windows Recursive DNS Spoofing Vulnerability
Microsoft Windows DNS Server is prone to a vulnerability that permits an attacker to spoof responses to DNS requests.
A successful attack will corrupt the DNS cache with attacker-specified content. This may aid in further attacks such as phishing.
Microsoft Windows DNS Server is prone to a vulnerability that permits an attacker to spoof responses to DNS requests.
A successful attack will corrupt the DNS cache with attacker-specified content. This may aid in further attacks such as phishing.
Exploit / POC
Microsoft Windows Recursive DNS Spoofing Vulnerability
An attacker could use standard network utilities to exploit this issue.
The following exploit code is available:
An attacker could use standard network utilities to exploit this issue.
The following exploit code is available:
Solution / Fix
Microsoft Windows Recursive DNS Spoofing Vulnerability
Solution:
The vendor released patches and an advisory to address this issue. Please see the references for more information.
Microsoft Windows 2000 Server SP2
Microsoft Windows Server 2003 Enterprise Edition SP1
Microsoft Windows 2000 Advanced Server SP1
Microsoft Windows 2000 Datacenter Server
Microsoft Windows 2000 Advanced Server SP2
Microsoft Windows Server 2003 Itanium SP1
Microsoft Windows Server 2003 Datacenter Edition
Microsoft Windows Server 2003 Itanium 0
Microsoft Windows 2000 Advanced Server SP4
Microsoft Windows Server 2003 SP2
Microsoft Windows 2000 Datacenter Server SP1
Microsoft Windows Server 2003 Enterprise Edition
Microsoft Windows Server 2003 Standard Edition SP2
Microsoft Windows 2000 Datacenter Server SP4
Microsoft Windows Server 2003 SP1
Microsoft Windows Server 2003 Itanium SP2
Microsoft Windows Server 2003 Web Edition
Microsoft Windows 2000 Advanced Server SP3
Microsoft Windows Server 2003 Web Edition SP1
Microsoft Windows 2000 Datacenter Server SP3
Microsoft Windows Server 2003 Web Edition SP2
Microsoft Windows Server 2003 Standard Edition SP1
Microsoft Windows 2000 Server SP3
Microsoft Windows Server 2003 Standard Edition
Microsoft Windows 2000 Datacenter Server SP2
Microsoft Windows 2000 Server SP4
Microsoft Windows 2000 Server SP1
Microsoft Windows Server 2003 Enterprise x64 Edition SP2
Microsoft Windows Server 2003 Enterprise x64 Edition
Microsoft Windows 2000 Advanced Server
Microsoft Windows 2000 Server
Solution:
The vendor released patches and an advisory to address this issue. Please see the references for more information.
Microsoft Windows 2000 Server SP2
-
Microsoft Security Update for Windows 2000 (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=c80fcd9b-d0f8 -44db-96fc-bf2ead054ff4&displaylang=en
Microsoft Windows Server 2003 Enterprise Edition SP1
-
Microsoft Security Update for Windows Server 2003 (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=ed8e2cb4-bcd9 -40fc-9ad6-46b364d0656d&displaylang=en
Microsoft Windows 2000 Advanced Server SP1
-
Microsoft Security Update for Windows 2000 (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=c80fcd9b-d0f8 -44db-96fc-bf2ead054ff4&displaylang=en
Microsoft Windows 2000 Datacenter Server
-
Microsoft Security Update for Windows 2000 (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=c80fcd9b-d0f8 -44db-96fc-bf2ead054ff4&displaylang=en
Microsoft Windows 2000 Advanced Server SP2
-
Microsoft Security Update for Windows 2000 (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=c80fcd9b-d0f8 -44db-96fc-bf2ead054ff4&displaylang=en
Microsoft Windows Server 2003 Itanium SP1
-
Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=f3ad67de-85ad -452d-a1e0-0af3faf969d6&displaylang=en
Microsoft Windows Server 2003 Datacenter Edition
-
Microsoft Security Update for Windows Server 2003 (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=ed8e2cb4-bcd9 -40fc-9ad6-46b364d0656d&displaylang=en
Microsoft Windows Server 2003 Itanium 0
-
Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=f3ad67de-85ad -452d-a1e0-0af3faf969d6&displaylang=en
Microsoft Windows 2000 Advanced Server SP4
-
Microsoft Security Update for Windows 2000 (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=c80fcd9b-d0f8 -44db-96fc-bf2ead054ff4&displaylang=en
Microsoft Windows Server 2003 SP2
-
Microsoft Security Update for Windows Server 2003 (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=ed8e2cb4-bcd9 -40fc-9ad6-46b364d0656d&displaylang=en
Microsoft Windows 2000 Datacenter Server SP1
-
Microsoft Security Update for Windows 2000 (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=c80fcd9b-d0f8 -44db-96fc-bf2ead054ff4&displaylang=en
Microsoft Windows Server 2003 Enterprise Edition
-
Microsoft Security Update for Windows Server 2003 (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=ed8e2cb4-bcd9 -40fc-9ad6-46b364d0656d&displaylang=en
Microsoft Windows Server 2003 Standard Edition SP2
-
Microsoft Security Update for Windows Server 2003 (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=ed8e2cb4-bcd9 -40fc-9ad6-46b364d0656d&displaylang=en
Microsoft Windows 2000 Datacenter Server SP4
-
Microsoft Security Update for Windows 2000 (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=c80fcd9b-d0f8 -44db-96fc-bf2ead054ff4&displaylang=en
Microsoft Windows Server 2003 SP1
-
Microsoft Security Update for Windows Server 2003 (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=ed8e2cb4-bcd9 -40fc-9ad6-46b364d0656d&displaylang=en
Microsoft Windows Server 2003 Itanium SP2
-
Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=f3ad67de-85ad -452d-a1e0-0af3faf969d6&displaylang=en
Microsoft Windows Server 2003 Web Edition
-
Microsoft Security Update for Windows Server 2003 (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=ed8e2cb4-bcd9 -40fc-9ad6-46b364d0656d&displaylang=en
Microsoft Windows 2000 Advanced Server SP3
-
Microsoft Security Update for Windows 2000 (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=c80fcd9b-d0f8 -44db-96fc-bf2ead054ff4&displaylang=en
Microsoft Windows Server 2003 Web Edition SP1
-
Microsoft Security Update for Windows Server 2003 (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=ed8e2cb4-bcd9 -40fc-9ad6-46b364d0656d&displaylang=en
Microsoft Windows 2000 Datacenter Server SP3
-
Microsoft Security Update for Windows 2000 (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=c80fcd9b-d0f8 -44db-96fc-bf2ead054ff4&displaylang=en
Microsoft Windows Server 2003 Web Edition SP2
-
Microsoft Security Update for Windows Server 2003 (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=ed8e2cb4-bcd9 -40fc-9ad6-46b364d0656d&displaylang=en
Microsoft Windows Server 2003 Standard Edition SP1
-
Microsoft Security Update for Windows Server 2003 (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=ed8e2cb4-bcd9 -40fc-9ad6-46b364d0656d&displaylang=en
Microsoft Windows 2000 Server SP3
-
Microsoft Security Update for Windows 2000 (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=c80fcd9b-d0f8 -44db-96fc-bf2ead054ff4&displaylang=en
Microsoft Windows Server 2003 Standard Edition
-
Microsoft Security Update for Windows Server 2003 (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=ed8e2cb4-bcd9 -40fc-9ad6-46b364d0656d&displaylang=en
Microsoft Windows 2000 Datacenter Server SP2
-
Microsoft Security Update for Windows 2000 (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=c80fcd9b-d0f8 -44db-96fc-bf2ead054ff4&displaylang=en
Microsoft Windows 2000 Server SP4
-
Microsoft Security Update for Windows 2000 (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=c80fcd9b-d0f8 -44db-96fc-bf2ead054ff4&displaylang=en
Microsoft Windows 2000 Server SP1
-
Microsoft Security Update for Windows 2000 (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=c80fcd9b-d0f8 -44db-96fc-bf2ead054ff4&displaylang=en
Microsoft Windows Server 2003 Enterprise x64 Edition SP2
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=d1323e14-ffa7 -4d03-a2a7-9240c192a75e&displaylang=en
Microsoft Windows Server 2003 Enterprise x64 Edition
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=d1323e14-ffa7 -4d03-a2a7-9240c192a75e&displaylang=en
Microsoft Windows 2000 Advanced Server
-
Microsoft Security Update for Windows 2000 (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=c80fcd9b-d0f8 -44db-96fc-bf2ead054ff4&displaylang=en
Microsoft Windows 2000 Server
-
Microsoft Security Update for Windows 2000 (KB941672)
http://www.microsoft.com/downloads/details.aspx?FamilyId=c80fcd9b-d0f8 -44db-96fc-bf2ead054ff4&displaylang=en
References
Microsoft Windows Recursive DNS Spoofing Vulnerability
References:
References:
- Microsoft Windows DNS Homepage (Microsoft)
- Microsoft Windows Homepage (Microsoft)
- Windows DNS Server Cache Poisoning (Amit Klein)
- After 6 months - fix available for Microsoft DNS cache poisoning attack (Amit Klein
) - Predictable DNS transaction IDs in Microsoft DNS Server (Alla Bezroutchko
) - ASA-2007-472 MS07-062 Vulnerability in DNS Could Allow Spoofing (941672) (Avaya)
- Microsoft Security Bulletin MS07-062 (Microsoft)
- Technical Cyber Security Alert TA07-317A: Microsoft Updates for Multiple Vulnera (US-CERT)
- Vulnerability Note VU#484649 Microsoft Windows DNS Server vulnerable to cache po (US-CERT)