Microsoft Host Integration Server RPC Remote Command Execution Vulnerability
BID:31620
Info
Microsoft Host Integration Server RPC Remote Command Execution Vulnerability
| Bugtraq ID: | 31620 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2008-3466 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 14 2008 12:00AM |
| Updated: | Nov 03 2008 04:15PM |
| Credit: | Stephen Fewer of Harmony Security |
| Vulnerable: |
Microsoft Host Integration Server 2006 0 Microsoft Host Integration Server 2004 SP1 Microsoft Host Integration Server 2004 0 Microsoft Host Integration Server 2000 Administrator Client 0 Microsoft Host Integration Server 2000 SP2 |
| Not Vulnerable: | |
Discussion
Microsoft Host Integration Server RPC Remote Command Execution Vulnerability
Microsoft Windows is prone to a remote command-execution vulnerability in the SNA service through a remote procedure call (RPC).
Successfully exploiting this issue would allow an attacker to execute arbitrary commands on an affected computer in the context of the affected service.
Microsoft Windows is prone to a remote command-execution vulnerability in the SNA service through a remote procedure call (RPC).
Successfully exploiting this issue would allow an attacker to execute arbitrary commands on an affected computer in the context of the affected service.
Exploit / POC
Microsoft Host Integration Server RPC Remote Command Execution Vulnerability
An attacker can exploit this issue by sending a specially crafted RPC request to a vulnerable computer.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product.
The following proof of concept is available for Immunity CANVAS:
https://www.immunityinc.com/downloads/immpartners/ms08_059.py
The following Metasploit Framwork exploit module is available:
An attacker can exploit this issue by sending a specially crafted RPC request to a vulnerable computer.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product.
The following proof of concept is available for Immunity CANVAS:
https://www.immunityinc.com/downloads/immpartners/ms08_059.py
The following Metasploit Framwork exploit module is available:
Solution / Fix
Microsoft Host Integration Server RPC Remote Command Execution Vulnerability
Solution:
Microsoft has released an advisory along with fixes to address this issue. Please see the references for more information.
Microsoft Host Integration Server 2000 Administrator Client 0
Microsoft Host Integration Server 2004 SP1
Microsoft Host Integration Server 2000 SP2
Microsoft Host Integration Server 2006 0
Microsoft Host Integration Server 2004 0
Solution:
Microsoft has released an advisory along with fixes to address this issue. Please see the references for more information.
Microsoft Host Integration Server 2000 Administrator Client 0
-
Microsoft Security Update for Microsoft Host Integration Server 2000 Admin Client
http://www.microsoft.com/downloads/details.aspx?familyid=41B49291-1231 -4E23-AEF7-818207453D56&displaylang=en
Microsoft Host Integration Server 2004 SP1
-
Microsoft Security Update for Microsoft Host Integration Server 2004 SP1 Client
http://www.microsoft.com/downloads/details.aspx?familyid=D776515C-09AA -4A04-876D-606BFC26A006&displaylang=en -
Microsoft Security Update for Microsoft Host Integration Server 2004 SP1 Server
http://www.microsoft.com/downloads/details.aspx?familyid=ECA756A1-CA56 -4481-B23C-53C159A4E08C&displaylang=en
Microsoft Host Integration Server 2000 SP2
-
Microsoft Security Update for Microsoft Host Integration Server 2000 Server
http://www.microsoft.com/downloads/details.aspx?familyid=11CCA58B-59A4 -4E93-9EB1-19B07C290A10
Microsoft Host Integration Server 2006 0
-
Microsoft Security Update for Microsoft Host Integration Server 2006 for x64
http://www.microsoft.com/downloads/details.aspx?familyid=05DA4540-4976 -458A-A612-7385D78695A2&displaylang=en -
Microsoft Security Update for Microsoft Host Integration Server 2006 for x86
http://www.microsoft.com/downloads/details.aspx?familyid=1AE79DA3-EC17 -4D4B-8011-D777A237AC93&displaylang=en
Microsoft Host Integration Server 2004 0
-
Microsoft Security Update for Microsoft Host Integration Server 2004 Client - English
http://www.microsoft.com/downloads/details.aspx?familyid=92CB54E7-F4FF -40A4-99CB-6257C4D8D4CD&displaylang=en -
Microsoft Security Update for Microsoft Host Integration Server 2004 Server
http://www.microsoft.com/downloads/details.aspx?familyid=9CA255ED-9334 -4848-AF94-49EF3078CDC0&displaylang=en
References
Microsoft Host Integration Server RPC Remote Command Execution Vulnerability
References:
References: