Microsoft IIS FTPd NLST Remote Buffer Overflow Vulnerability
BID:36189
Info
Microsoft IIS FTPd NLST Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 36189 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-3023 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 31 2009 12:00AM |
| Updated: | Oct 07 2010 08:51AM |
| Credit: | Kingcope |
| Vulnerable: |
Microsoft IIS 6.0 Microsoft IIS 5.1 Microsoft IIS 5.0 |
| Not Vulnerable: |
Microsoft IIS 7.5 |
Discussion
Microsoft IIS FTPd NLST Remote Buffer Overflow Vulnerability
Microsoft IIS is prone to a remote stack-based buffer-overflow vulnerability affecting the application's FTP server.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
This issue affects the following:
IIS 5.0
IIS 5.1
IIS 6.0 (denial of service only)
IIS 7.0 (denial of service only)
Note that Microsoft IIS 7.0 with FTP Service 7.5 is not affected.
Other versions may also be affected.
NOTE: This issue cannot be exploited to execute arbitrary code on IIS 6.0 or 7.0.
NOTE (September 1, 2009): This issue can be exploited to execute arbitrary code with SYSTEM-level privileges on IIS 5.0.
UPDATE (September 8, 2009); This issue may be related to a vulnerability reported in 1999 affecting IIS 3 and IIS 4. We will update this BID as more details emerge.
Microsoft IIS is prone to a remote stack-based buffer-overflow vulnerability affecting the application's FTP server.
An attacker can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
This issue affects the following:
IIS 5.0
IIS 5.1
IIS 6.0 (denial of service only)
IIS 7.0 (denial of service only)
Note that Microsoft IIS 7.0 with FTP Service 7.5 is not affected.
Other versions may also be affected.
NOTE: This issue cannot be exploited to execute arbitrary code on IIS 6.0 or 7.0.
NOTE (September 1, 2009): This issue can be exploited to execute arbitrary code with SYSTEM-level privileges on IIS 5.0.
UPDATE (September 8, 2009); This issue may be related to a vulnerability reported in 1999 affecting IIS 3 and IIS 4. We will update this BID as more details emerge.
Exploit / POC
Microsoft IIS FTPd NLST Remote Buffer Overflow Vulnerability
Microsoft reported limited in-the-wild exploitation of this issue.
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following pattern can trigger a denial of service, without write access to the server, assuming a directory name that starts with 'A' and is at least 14 characters in length:
NLST [Ax206]*/../A*/../A*/../A*/../A*/../A*/../A*/../A*/\r\n
The following exploits are available:
Microsoft reported limited in-the-wild exploitation of this issue.
A working commercial exploit is available through VUPEN Security - Exploit and PoCs Service. This exploit is not otherwise publicly available or known to be circulating in the wild.
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The following pattern can trigger a denial of service, without write access to the server, assuming a directory name that starts with 'A' and is at least 14 characters in length:
NLST [Ax206]*/../A*/../A*/../A*/../A*/../A*/../A*/../A*/\r\n
The following exploits are available:
Solution / Fix
Microsoft IIS FTPd NLST Remote Buffer Overflow Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Solution:
The vendor released an update to address this issue. Please see the references for more information.
References
Microsoft IIS FTPd NLST Remote Buffer Overflow Vulnerability
References:
References:
- isowarez.pdf (Kingcope)
- Microsoft IIS FTP 5.0 Remote SYSTEM Exploit (Offensive Security)
- Microsoft IIS Homepage (Microsoft)
- Microsoft Security Advisory 975191 Released (Microsoft Security Response Center)
- Microsoft Security Advisory 975191 Revised (Microsoft)
- New vulnerability in IIS5 and IIS6 (Microsoft Security Research & Defense)
- Re: [Full-disclosure] Microsoft Internet Information Server ftpd zeroday (Guido Landi (listskeamera.org))
- Re: [Full-disclosure] Microsoft Internet Information Server ftpd zeroday (Thierry Zoller
) - Microsoft Security Advisory (975191) Vulnerability in Internet Information Servi (Microsoft)
- Microsoft Security Bulletin MS09-053 (Microsoft)
- Vulnerability Note VU#276653 Microsoft Internet Information Server (IIS) FTP ser (US-CERT)