Microsoft ASP.NET Request Scheduling Denial Of Service Vulnerability
BID:35985
Info
Microsoft ASP.NET Request Scheduling Denial Of Service Vulnerability
| Bugtraq ID: | 35985 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2009-1536 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 11 2009 12:00AM |
| Updated: | Aug 11 2009 07:23PM |
| Credit: | Alexander Pfandt of Digitaria |
| Vulnerable: |
Microsoft .NET Framework 3.5 SP1 Microsoft .NET Framework 3.5 Microsoft .NET Framework 2.0 SP2 Microsoft .NET Framework 2.0 SP1 Microsoft .NET Framework 2.0 |
| Not Vulnerable: | |
Discussion
Microsoft ASP.NET Request Scheduling Denial Of Service Vulnerability
Microsoft ASP.NET is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause the application pool on the affected webserver to become unresponsive, denying service to legitimate users.
NOTE: This issue only affects ASP.NET on webservers running IIS 7 in integrated mode.
Microsoft ASP.NET is prone to a denial-of-service vulnerability.
An attacker can exploit this issue to cause the application pool on the affected webserver to become unresponsive, denying service to legitimate users.
NOTE: This issue only affects ASP.NET on webservers running IIS 7 in integrated mode.
Exploit / POC
Microsoft ASP.NET Request Scheduling Denial Of Service Vulnerability
An attacker can use readily available tools to exploit this issue.
An attacker can use readily available tools to exploit this issue.
Solution / Fix
Microsoft ASP.NET Request Scheduling Denial Of Service Vulnerability
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
Microsoft .NET Framework 2.0 SP1
Microsoft .NET Framework 3.5 SP1
Microsoft .NET Framework 2.0 SP2
Microsoft .NET Framework 3.5
Solution:
The vendor has released an advisory and fixes. Please see the references for details.
Microsoft .NET Framework 2.0 SP1
-
Microsoft Microsoft .NET Framework 2.0 Service Pack 1 ASP.NET Security Update for Windows Vista
http://www.microsoft.com/downloads/details.aspx?familyid=d42444bb-5030 -4b47-87fa-9df3a8c640ff -
Microsoft Microsoft .NET Framework 2.0 Service Pack 1 ASP.NET Security Update for Windows Vista Service Pack 1
http://www.microsoft.com/downloads/details.aspx?familyid=cbf40800-f3b3 -43da-ace1-d942d3378ccd
Microsoft .NET Framework 3.5 SP1
-
Microsoft Microsoft .NET Framework 2.0 Service Pack 2 ASP.NET Security Update for Windows Vista
http://www.microsoft.com/downloads/details.aspx?familyid=310f3aa6-c264 -45a2-b24a-3f178b41830e -
Microsoft Microsoft .NET Framework 2.0 Service Pack 2 ASP.NET Security Update for Windows Vista Service Pack 1
http://www.microsoft.com/downloads/details.aspx?familyid=87c4a868-b3b5 -467d-96a4-633532ab548f
Microsoft .NET Framework 2.0 SP2
-
Microsoft Microsoft .NET Framework 2.0 Service Pack 2 ASP.NET Security Update for Windows Vista
http://www.microsoft.com/downloads/details.aspx?familyid=310f3aa6-c264 -45a2-b24a-3f178b41830e -
Microsoft Microsoft .NET Framework 2.0 Service Pack 2 ASP.NET Security Update for Windows Vista Service Pack 1
http://www.microsoft.com/downloads/details.aspx?familyid=87c4a868-b3b5 -467d-96a4-633532ab548f
Microsoft .NET Framework 3.5
-
Microsoft Microsoft .NET Framework 2.0 Service Pack 1 ASP.NET Security Update for Windows Vista
http://www.microsoft.com/downloads/details.aspx?familyid=d42444bb-5030 -4b47-87fa-9df3a8c640ff -
Microsoft Microsoft .NET Framework 2.0 Service Pack 1 ASP.NET Security Update for Windows Vista Service Pack 1
http://www.microsoft.com/downloads/details.aspx?familyid=cbf40800-f3b3 -43da-ace1-d942d3378ccd
References
Microsoft ASP.NET Request Scheduling Denial Of Service Vulnerability
References:
References:
- Microsoft .NET Framework Developer Center (Microsoft)
- Microsoft Homepage (Microsoft)
- MS09-035: ASP.NET Denial-of-Service vulnerability (Microsoft)
- Microsoft Security Bulletin MS09-036 (Microsoft)