Microsoft Windows NT RPC Endpoint Mapper Denial of Service Vulnerability
BID:3313
Info
Microsoft Windows NT RPC Endpoint Mapper Denial of Service Vulnerability
| Bugtraq ID: | 3313 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 10 2001 12:00AM |
| Updated: | Sep 10 2001 12:00AM |
| Credit: | This vulnerability was discovered by Seiichi Tatsukawa of Rational Software (http://www.rational.com). |
| Vulnerable: |
Microsoft Windows NT Workstation 4.0 SP6a Microsoft Windows NT Workstation 4.0 SP6 Microsoft Windows NT Workstation 4.0 SP5 Microsoft Windows NT Workstation 4.0 SP4 Microsoft Windows NT Workstation 4.0 SP3 Microsoft Windows NT Workstation 4.0 SP2 Microsoft Windows NT Workstation 4.0 SP1 Microsoft Windows NT Workstation 4.0 Microsoft Windows NT Terminal Server 4.0 SP6 Microsoft Windows NT Terminal Server 4.0 SP5 Microsoft Windows NT Terminal Server 4.0 SP4 Microsoft Windows NT Terminal Server 4.0 SP3 Microsoft Windows NT Terminal Server 4.0 SP2 Microsoft Windows NT Terminal Server 4.0 SP1 Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6 Microsoft Windows NT Enterprise Server 4.0 SP5 Microsoft Windows NT Enterprise Server 4.0 SP4 Microsoft Windows NT Enterprise Server 4.0 SP3 Microsoft Windows NT Enterprise Server 4.0 SP2 Microsoft Windows NT Enterprise Server 4.0 SP1 Microsoft Windows NT Enterprise Server 4.0 |
| Not Vulnerable: |
Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows 2000 Terminal Services SP3 Microsoft Windows 2000 Terminal Services SP2 Microsoft Windows 2000 Terminal Services SP1 Microsoft Windows 2000 Terminal Services Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
Discussion
Microsoft Windows NT RPC Endpoint Mapper Denial of Service Vulnerability
Remote Procedure Call (RPC) services are dynamically assigned TCP and UDP ports. The RPC Endpoint Mapper service communicates on which port an RPC service resides to a requesting client.
When the RPC Endpoint Mapper, which typically resides on port 135, is sent a particular type of malformed data, it can cause the service to fail. This will cause all client attempts to access any RPC services on the target host to fail, resulting in a denial of services.
Remote Procedure Call (RPC) services are dynamically assigned TCP and UDP ports. The RPC Endpoint Mapper service communicates on which port an RPC service resides to a requesting client.
When the RPC Endpoint Mapper, which typically resides on port 135, is sent a particular type of malformed data, it can cause the service to fail. This will cause all client attempts to access any RPC services on the target host to fail, resulting in a denial of services.
Exploit / POC
Microsoft Windows NT RPC Endpoint Mapper Denial of Service Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Windows NT RPC Endpoint Mapper Denial of Service Vulnerability
Solution:
Microsoft has released a hotfix which addresses this issue.
The linked fix was updated by Microsoft on March 17, 2003 for unspecified reasons. Administrators who have already applied the fix are advised to apply the new version.
Microsoft Windows NT Workstation 4.0 SP6a
Microsoft Windows NT Enterprise Server 4.0 SP6a
Microsoft Windows NT Server 4.0 SP6a
Solution:
Microsoft has released a hotfix which addresses this issue.
The linked fix was updated by Microsoft on March 17, 2003 for unspecified reasons. Administrators who have already applied the fix are advised to apply the new version.
Microsoft Windows NT Workstation 4.0 SP6a
-
Microsoft Q305399
http://download.microsoft.com/download/winntsp/Patch/Q305399/NT4/EN-US /Q305399i.exe
Microsoft Windows NT Enterprise Server 4.0 SP6a
-
Microsoft Q305399
http://download.microsoft.com/download/winntsp/Patch/Q305399/NT4/EN-US /Q305399i.exe
Microsoft Windows NT Server 4.0 SP6a
References
Microsoft Windows NT RPC Endpoint Mapper Denial of Service Vulnerability
References:
References: