Microsoft Windows WINS Server Network Packet Remote Heap Buffer Overflow Vulnerability
BID:35980
Info
Microsoft Windows WINS Server Network Packet Remote Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 35980 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-1923 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 11 2009 12:00AM |
| Updated: | Aug 21 2009 03:50PM |
| Credit: | TippingPoint and the Zero Day Initiative |
| Vulnerable: |
Microsoft Windows Server 2003 x64 SP2 Microsoft Windows Server 2003 x64 SP1 Microsoft Windows Server 2003 Web Edition SP2 Microsoft Windows Server 2003 Web Edition SP1 Microsoft Windows Server 2003 Web Edition Microsoft Windows Server 2003 Standard x64 Edition Microsoft Windows Server 2003 Standard Edition SP2 Microsoft Windows Server 2003 Standard Edition SP1 Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Itanium SP2 Microsoft Windows Server 2003 Itanium SP1 Microsoft Windows Server 2003 Itanium 0 Microsoft Windows Server 2003 Enterprise x64 Edition SP2 Microsoft Windows Server 2003 Enterprise x64 Edition Microsoft Windows Server 2003 Enterprise Edition Itanium SP1 Microsoft Windows Server 2003 Enterprise Edition Itanium 0 Microsoft Windows Server 2003 Enterprise Edition SP1 Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Datacenter x64 Edition SP2 Microsoft Windows Server 2003 Datacenter x64 Edition Microsoft Windows Server 2003 Datacenter Edition Itanium SP1 Beta 1 Microsoft Windows Server 2003 Datacenter Edition Itanium SP1 Microsoft Windows Server 2003 Datacenter Edition Itanium 0 Microsoft Windows Server 2003 Datacenter Edition SP1 Microsoft Windows Server 2003 Datacenter Edition Microsoft Windows Server 2003 SP2 Microsoft Windows Server 2003 SP1 Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Discussion
Microsoft Windows WINS Server Network Packet Remote Heap Buffer Overflow Vulnerability
The Microsoft Windows WINS Server is prone to a remote heap-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successfully exploiting this issue will completely compromise affected computers. Failed exploit attempts will result in a denial-of-service condition.
The Microsoft Windows WINS Server is prone to a remote heap-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successfully exploiting this issue will completely compromise affected computers. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Microsoft Windows WINS Server Network Packet Remote Heap Buffer Overflow Vulnerability
ISC SANS has reported that this issue is being actively exploited in the wild. Note that Symantec has not confirmed any active exploits.
ISC SANS has reported that this issue is being actively exploited in the wild. Note that Symantec has not confirmed any active exploits.
Solution / Fix
Microsoft Windows WINS Server Network Packet Remote Heap Buffer Overflow Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft Windows 2000 Advanced Server SP4
Microsoft Windows Server 2003 SP2
Microsoft Windows Server 2003 Datacenter x64 Edition SP2
Microsoft Windows Server 2003 Standard Edition SP2
Microsoft Windows 2000 Datacenter Server SP4
Microsoft Windows Server 2003 Itanium SP2
Microsoft Windows Server 2003 Web Edition SP2
Microsoft Windows Server 2003 x64 SP2
Microsoft Windows Server 2003 Enterprise x64 Edition SP2
Microsoft Windows 2000 Professional SP4
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft Windows 2000 Advanced Server SP4
-
Microsoft Security Update for Windows 2000 (KB969883)
http://www.microsoft.com/downloads/details.aspx?familyid=b5b9228a-66c0 -49e6-afde-cc2825a6851f
Microsoft Windows Server 2003 SP2
-
Microsoft Security Update for Windows Server 2003 (KB969883)
http://www.microsoft.com/downloads/details.aspx?familyid=3a8d8ef9-ad41 -4237-9cbb-daecfd8f216c
Microsoft Windows Server 2003 Datacenter x64 Edition SP2
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB969883)
http://www.microsoft.com/downloads/details.aspx?familyid=e132d051-4444 -4ef1-9b6f-2d7da9d2e88e
Microsoft Windows Server 2003 Standard Edition SP2
-
Microsoft Security Update for Windows Server 2003 (KB969883)
http://www.microsoft.com/downloads/details.aspx?familyid=3a8d8ef9-ad41 -4237-9cbb-daecfd8f216c
Microsoft Windows 2000 Datacenter Server SP4
-
Microsoft Security Update for Windows 2000 (KB969883)
http://www.microsoft.com/downloads/details.aspx?familyid=b5b9228a-66c0 -49e6-afde-cc2825a6851f
Microsoft Windows Server 2003 Itanium SP2
-
Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB969883)
http://www.microsoft.com/downloads/details.aspx?familyid=96c3f496-7b2f -4dbc-b484-216c9943c2b1
Microsoft Windows Server 2003 Web Edition SP2
-
Microsoft Security Update for Windows Server 2003 (KB969883)
http://www.microsoft.com/downloads/details.aspx?familyid=3a8d8ef9-ad41 -4237-9cbb-daecfd8f216c
Microsoft Windows Server 2003 x64 SP2
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB969883)
http://www.microsoft.com/downloads/details.aspx?familyid=e132d051-4444 -4ef1-9b6f-2d7da9d2e88e
Microsoft Windows Server 2003 Enterprise x64 Edition SP2
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB969883)
http://www.microsoft.com/downloads/details.aspx?familyid=e132d051-4444 -4ef1-9b6f-2d7da9d2e88e
Microsoft Windows 2000 Professional SP4
-
Microsoft Security Update for Windows 2000 (KB969883)
http://www.microsoft.com/downloads/details.aspx?familyid=b5b9228a-66c0 -49e6-afde-cc2825a6851f
References
Microsoft Windows WINS Server Network Packet Remote Heap Buffer Overflow Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- MS09-039 exploit in the wild? (ISC SANS)
- MS09-039: More information about the WINS security bulletin (Microsoft)
- ZDI-09-053: Microsoft Windows WINS Service Heap Overflow Vulnerability (ZDI Disclosures
) - Microsoft Security Bulletin MS09-039 (Microsoft)