MS Index Server and Indexing Service ISAPI Extension Buffer Overflow Vulnerability
BID:2880
Info
MS Index Server and Indexing Service ISAPI Extension Buffer Overflow Vulnerability
| Bugtraq ID: | 2880 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2001-0500 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 18 2001 12:00AM |
| Updated: | Nov 26 2009 09:05PM |
| Credit: | Discovered by Riley Hassell of eEye Digital Security and posted in a Microsoft Security Bulletin MS01-033 on June 18, 2001. |
| Vulnerable: |
Microsoft Indexing Services for Windows 2000 Microsoft Index Server 2.0 Cisco uOne Enterprise Edition Cisco uOne 4.0 Cisco uOne 3.0 Cisco uOne 2.0 Cisco uOne 1.0 Cisco Unity Server 4.0 Cisco Unity Server 3.3 Cisco Unity Server 3.2 Cisco Unity Server 3.1 Cisco Unity Server 3.0 Cisco Unity Server 2.46 Cisco Unity Server 2.4 Cisco Unity Server 2.3 Cisco Unity Server 2.2 Cisco Unity Server 2.1 Cisco Unity Server 2.0 Cisco Unity Server Cisco Trailhead Cisco Media Blender Cisco IP/VC 3540 Application Server Cisco ICS Firmware 2.0 Cisco ICS Firmware 1.0 Cisco ICS 7750 Cisco Dynamic Content Adapter Cisco Collaboration Server Cisco Call Manager 4.0 Cisco Call Manager 3.3 (3) Cisco Call Manager 3.3 Cisco Call Manager 3.2 Cisco Call Manager 3.1 (3a) Cisco Call Manager 3.1 (2) Cisco Call Manager 3.1 Cisco Call Manager 3.0 Cisco Call Manager 2.0 Cisco Call Manager 1.0 Cisco Call Manager Cisco Building Broadband Service Manager (BBSM) 5.2 Cisco Building Broadband Service Manager (BBSM) 5.1 Cisco Building Broadband Service Manager (BBSM) 5.0 Cisco Building Broadband Service Manager (BBSM) 4.5 Cisco Building Broadband Service Manager (BBSM) 4.4 Cisco Building Broadband Service Manager (BBSM) 4.3 Cisco Building Broadband Service Manager (BBSM) 4.2 Cisco Building Broadband Service Manager (BBSM) 4.0.1 Cisco Building Broadband Service Manager (BBSM) 3.0 Cisco Building Broadband Service Manager (BBSM) 2.5.1 |
| Not Vulnerable: | |
Discussion
MS Index Server and Indexing Service ISAPI Extension Buffer Overflow Vulnerability
Windows Index Server ships with Windows NT 4.0 Option Pack; Windows Indexing Service ships with Windows 2000. An unchecked buffer resides in the 'idq.dll' ISAPI extension associated with each service. A maliciously crafted request could allow arbitrary code to run on the host in the Local System context.
Note that Index Server and Indexing Service do not need to be running for an attacker to exploit this issue. Since 'idq.dll' is installed by default when IIS is installed, IIS would need to be the only service running.
Note also that this vulnerability is currently being exploited by the 'Code Red' worm. In addition, all products that run affected versions of IIS are also vulnerable.
**UPDATE**: An aggressive worm that actively exploits this vulnerability is believed to be in the wild.
Windows Index Server ships with Windows NT 4.0 Option Pack; Windows Indexing Service ships with Windows 2000. An unchecked buffer resides in the 'idq.dll' ISAPI extension associated with each service. A maliciously crafted request could allow arbitrary code to run on the host in the Local System context.
Note that Index Server and Indexing Service do not need to be running for an attacker to exploit this issue. Since 'idq.dll' is installed by default when IIS is installed, IIS would need to be the only service running.
Note also that this vulnerability is currently being exploited by the 'Code Red' worm. In addition, all products that run affected versions of IIS are also vulnerable.
**UPDATE**: An aggressive worm that actively exploits this vulnerability is believed to be in the wild.
Exploit / POC
MS Index Server and Indexing Service ISAPI Extension Buffer Overflow Vulnerability
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Exploits are available.
A Metasploit exploit module is also available.
UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Exploits are available.
A Metasploit exploit module is also available.
Solution / Fix
MS Index Server and Indexing Service ISAPI Extension Buffer Overflow Vulnerability
Solution:
Microsoft has released a patch. Please see the references for details.
NOTE: Reports indicate that post-patch systems may be vulnerable to a denial of service; administrators are advised to reapply the newer patch if it is not installed and to remove the .ida/.idq mappings.
Microsoft has released the following tool that rectifies the damage caused by the 'Code Red II' worm:
http://www.microsoft.com/technet/itsolutions/security/tools/redfix.asp
Microsoft Index Server 2.0
Microsoft Indexing Services for Windows 2000
Solution:
Microsoft has released a patch. Please see the references for details.
NOTE: Reports indicate that post-patch systems may be vulnerable to a denial of service; administrators are advised to reapply the newer patch if it is not installed and to remove the .ida/.idq mappings.
Microsoft has released the following tool that rectifies the damage caused by the 'Code Red II' worm:
http://www.microsoft.com/technet/itsolutions/security/tools/redfix.asp
Microsoft Index Server 2.0
-
Microsoft Q300972
http://download.microsoft.com/download/winntsp/Patch/q300972/NT4/EN-US /Q300972i.exe
Microsoft Indexing Services for Windows 2000
References
MS Index Server and Indexing Service ISAPI Extension Buffer Overflow Vulnerability
References:
References:
- A Very Real and Present Threat to the Internet (Microsoft)
- All versions of Microsoft Internet Information Services Remote buffer overflow ( (eEye Digital Security)
- CERT Advisory CA-2001-23: Continuing Threat of the "Code Red" Worm (CERT)
- CERT Incident Note IN-2001-08: "Code Red" Worm Exploiting Buffer Overflow in IIS (CERT)
- CERT Incident Note IN-2001-09: "Code Red II:" Another Worm Exploiting Buffer Ove (CERT)
- CERT Incident Note IN-2001-10: "Code Red" Worm Crashes IIS 4.0 Servers with URL (CERT)
- CERT® Advisory CA-2001-13 Buffer Overflow In IIS Indexing Service DLL (CERT)
- CERT® Advisory CA-2001-19 "Code Red" Worm Exploiting Buffer Overflow In IIS Inde (CERT)
- Cisco Security Advisory: "Code Red" Worm - Customer Impact (Cisco)
- IIS IDA-IDQ exploit (CORE Security)
- Microsoft Internet Information Server 4.0 Security Checklist (Microsoft)
- Microsoft Security Bulletin MS01-033 (Microsoft)
- Post-Windows NT 4.0 Service Pack 6a Security Rollup Package (SRP) Now Available (Microsoft)
- Secure Internet Information Services 5 Checklist (Microsoft)
- Tool to eliminate the obvious effects of the Code Red II worm (Microsoft)
- Using Network-Based Application Recognition and Access Control Lists for Blockin (Cisco Systems)
- X-Force Response to Concern About the "Code Red" Worm (ISS)