Microsoft Windows WINS Server Network Buffer Length Integer Overflow Vulnerability
BID:35981
Info
Microsoft Windows WINS Server Network Buffer Length Integer Overflow Vulnerability
| Bugtraq ID: | 35981 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-1924 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 11 2009 12:00AM |
| Updated: | Sep 08 2009 03:31PM |
| Credit: | LiGen of National University of Defense Technology |
| Vulnerable: |
Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Advanced Server SP4 |
| Not Vulnerable: | |
Discussion
Microsoft Windows WINS Server Network Buffer Length Integer Overflow Vulnerability
The Microsoft Windows WINS Server is prone to a remote integer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successful exploits will completely compromise affected computers. Failed exploit attempts will result in a denial-of-service condition.
The Microsoft Windows WINS Server is prone to a remote integer-overflow vulnerability.
An attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successful exploits will completely compromise affected computers. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Microsoft Windows WINS Server Network Buffer Length Integer Overflow Vulnerability
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
The following commercial proof of concept is available for Immunity CANVAS:
https://www.immunityinc.com/downloads/immpartners/ms09_039.tgz
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
The following commercial proof of concept is available for Immunity CANVAS:
https://www.immunityinc.com/downloads/immpartners/ms09_039.tgz
Solution / Fix
Microsoft Windows WINS Server Network Buffer Length Integer Overflow Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft Windows 2000 Advanced Server SP4
Microsoft Windows 2000 Professional SP4
Microsoft Windows 2000 Datacenter Server SP4
Microsoft Windows 2000 Server SP4
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft Windows 2000 Advanced Server SP4
-
Microsoft Security Update for Windows 2000 (KB969883)
http://www.microsoft.com/downloads/details.aspx?familyid=b5b9228a-66c0 -49e6-afde-cc2825a6851f
Microsoft Windows 2000 Professional SP4
-
Microsoft Security Update for Windows 2000 (KB969883)
http://www.microsoft.com/downloads/details.aspx?familyid=b5b9228a-66c0 -49e6-afde-cc2825a6851f
Microsoft Windows 2000 Datacenter Server SP4
-
Microsoft Security Update for Windows 2000 (KB969883)
http://www.microsoft.com/downloads/details.aspx?familyid=b5b9228a-66c0 -49e6-afde-cc2825a6851f
Microsoft Windows 2000 Server SP4
-
Microsoft Security Update for Windows 2000 (KB969883)
http://www.microsoft.com/downloads/details.aspx?familyid=b5b9228a-66c0 -49e6-afde-cc2825a6851f
References
Microsoft Windows WINS Server Network Buffer Length Integer Overflow Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- Microsoft Security Bulletin MS09-039 (Microsoft)