Microsoft Windows SMB2 '_Smb2ValidateProviderCallback()' Remote Code Execution Vulnerability
BID:36299
Info
Microsoft Windows SMB2 '_Smb2ValidateProviderCallback()' Remote Code Execution Vulnerability
| Bugtraq ID: | 36299 |
| Class: | Input Validation Error |
| CVE: |
CVE-2009-3103 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 07 2009 12:00AM |
| Updated: | Aug 17 2010 05:04PM |
| Credit: | Laurent Gaffié |
| Vulnerable: |
Microsoft Windows Vista x64 Edition SP2 Microsoft Windows Vista x64 Edition SP1 Microsoft Windows Vista x64 Edition 0 Microsoft Windows Vista Ultimate 64-bit edition SP2 Microsoft Windows Vista Ultimate 64-bit edition SP1 Microsoft Windows Vista Ultimate 64-bit edition 0 Microsoft Windows Vista Home Premium 64-bit edition SP2 Microsoft Windows Vista Home Premium 64-bit edition SP1 Microsoft Windows Vista Home Premium 64-bit edition 0 Microsoft Windows Vista Home Basic 64-bit edition SP2 Microsoft Windows Vista Home Basic 64-bit edition SP1 Microsoft Windows Vista Home Basic 64-bit edition 0 Microsoft Windows Vista Enterprise 64-bit edition SP2 Microsoft Windows Vista Enterprise 64-bit edition SP1 Microsoft Windows Vista Enterprise 64-bit edition 0 Microsoft Windows Vista Business 64-bit edition SP2 Microsoft Windows Vista Business 64-bit edition SP1 Microsoft Windows Vista Business 64-bit edition 0 Microsoft Windows Vista Ultimate SP2 Microsoft Windows Vista Ultimate SP1 Microsoft Windows Vista Ultimate Microsoft Windows Vista Home Premium SP2 Microsoft Windows Vista Home Premium SP1 Microsoft Windows Vista Home Premium Microsoft Windows Vista Home Basic SP2 Microsoft Windows Vista Home Basic SP1 Microsoft Windows Vista Home Basic Microsoft Windows Vista Enterprise SP2 Microsoft Windows Vista Enterprise SP1 Microsoft Windows Vista Enterprise Microsoft Windows Vista Business SP2 Microsoft Windows Vista Business SP1 Microsoft Windows Vista Business Microsoft Windows Server 2008 Standard Edition SP2 Microsoft Windows Server 2008 Standard Edition 0 Microsoft Windows Server 2008 for x64-based Systems SP2 Microsoft Windows Server 2008 for x64-based Systems 0 Microsoft Windows Server 2008 for Itanium-based Systems SP2 Microsoft Windows Server 2008 for Itanium-based Systems 0 Microsoft Windows Server 2008 for 32-bit Systems SP2 Microsoft Windows Server 2008 for 32-bit Systems 0 Microsoft Windows Server 2008 Enterprise Edition SP2 Microsoft Windows Server 2008 Enterprise Edition 0 Microsoft Windows Server 2008 Datacenter Edition SP2 Microsoft Windows Server 2008 Datacenter Edition 0 Microsoft Windows 7 RC Microsoft Windows 7 beta |
| Not Vulnerable: | |
Discussion
Microsoft Windows SMB2 '_Smb2ValidateProviderCallback()' Remote Code Execution Vulnerability
Microsoft Windows is prone to a remote code-execution vulnerability when processing the protocol headers for the Server Message Block (SMB) Negotiate Protocol Request.
NOTE: Reportedly, for this issue to be exploitable, file sharing must be enabled.
An attacker can exploit this issue to execute code with SYSTEM-level privileges; failed exploit attempts will likely cause denial-of-service conditions.
Windows 7 RC, Vista and 2008 Server are vulnerable; other versions may also be affected.
NOTE: Reportedly, Windows XP and 2000 are not affected.
UPDATE (September 9, 2009): Symantec has confirmed the issue on Windows Vista SP1 and Windows Server 2008.
Microsoft Windows is prone to a remote code-execution vulnerability when processing the protocol headers for the Server Message Block (SMB) Negotiate Protocol Request.
NOTE: Reportedly, for this issue to be exploitable, file sharing must be enabled.
An attacker can exploit this issue to execute code with SYSTEM-level privileges; failed exploit attempts will likely cause denial-of-service conditions.
Windows 7 RC, Vista and 2008 Server are vulnerable; other versions may also be affected.
NOTE: Reportedly, Windows XP and 2000 are not affected.
UPDATE (September 9, 2009): Symantec has confirmed the issue on Windows Vista SP1 and Windows Server 2008.
Exploit / POC
Microsoft Windows SMB2 '_Smb2ValidateProviderCallback()' Remote Code Execution Vulnerability
A working remote commercial exploit is available for Immunity CANVAS. This exploit is not otherwise publicly available or known to be circulating in the wild:
https://www.immunityinc.com/downloads/immpartners/smb2_negotiate_remote.tgz
The following exploits and proofs of concept are available:
A working remote commercial exploit is available for Immunity CANVAS. This exploit is not otherwise publicly available or known to be circulating in the wild:
https://www.immunityinc.com/downloads/immpartners/smb2_negotiate_remote.tgz
The following exploits and proofs of concept are available:
- /data/vulnerabilities/exploits/36299.py
- /data/vulnerabilities/exploits/36299-2.rb
- /data/vulnerabilities/exploits/36299-3.c
- /data/vulnerabilities/exploits/36299-4.c
- /data/vulnerabilities/exploits/36299-5.c
- /data/vulnerabilities/exploits/36299-smb2_negotiate.sh
- /data/vulnerabilities/exploits/36299-teardrop_tng.rb
- /data/vulnerabilities/exploits/36299.jar
- /data/vulnerabilities/exploits/36299.exp
- /data/vulnerabilities/exploits/36299-11.pl
- /data/vulnerabilities/exploits/36299_metasploit.rb
- /data/vulnerabilities/exploits/36299_metasploit-2.rb
- /data/vulnerabilities/exploits/smb2_exploit_release.zip
- /data/vulnerabilities/exploits/36299.pl
Solution / Fix
Microsoft Windows SMB2 '_Smb2ValidateProviderCallback()' Remote Code Execution Vulnerability
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Microsoft Windows Server 2008 for x64-based Systems 0
Microsoft Windows Server 2008 for Itanium-based Systems SP2
Microsoft Windows Server 2008 for 32-bit Systems SP2
Microsoft Windows Vista x64 Edition 0
Microsoft Windows Server 2008 for x64-based Systems SP2
Microsoft Windows Server 2008 for Itanium-based Systems 0
Microsoft Windows Vista x64 Edition SP2
Microsoft Windows Server 2008 for 32-bit Systems 0
Microsoft Windows Vista x64 Edition SP1
Solution:
The vendor released an update to address this issue. Please see the references for more information.
Microsoft Windows Server 2008 for x64-based Systems 0
-
Microsoft Security Update for Windows Server 2008 x64 Edition (KB975517)
http://www.microsoft.com/downloads/details.aspx?familyid=aff6f9c7-4a72 -48f2-b750-204d796c7daa
Microsoft Windows Server 2008 for Itanium-based Systems SP2
-
Microsoft Security Update for Windows Server 2008 for Itanium-based Systems (KB975517)
http://www.microsoft.com/downloads/details.aspx?familyid=7b70108b-7f59 -4898-ab4e-76be990de878
Microsoft Windows Server 2008 for 32-bit Systems SP2
-
Microsoft Security Update for Windows Server 2008 (KB975517)
http://www.microsoft.com/downloads/details.aspx?familyid=ff6bfcf3-76c9 -4c45-b57d-22f94458dd6e
Microsoft Windows Vista x64 Edition 0
-
Microsoft Security Update for Windows Vista for x64-based Systems (KB975517)
http://www.microsoft.com/downloads/details.aspx?familyid=62ed5d0a-5ca6 -4942-80c9-7808b14cb6b5
Microsoft Windows Server 2008 for x64-based Systems SP2
-
Microsoft Security Update for Windows Server 2008 x64 Edition (KB975517)
http://www.microsoft.com/downloads/details.aspx?familyid=aff6f9c7-4a72 -48f2-b750-204d796c7daa
Microsoft Windows Server 2008 for Itanium-based Systems 0
-
Microsoft Security Update for Windows Server 2008 for Itanium-based Systems (KB975517)
http://www.microsoft.com/downloads/details.aspx?familyid=7b70108b-7f59 -4898-ab4e-76be990de878
Microsoft Windows Vista x64 Edition SP2
-
Microsoft Security Update for Windows Vista for x64-based Systems (KB975517)
http://www.microsoft.com/downloads/details.aspx?familyid=62ed5d0a-5ca6 -4942-80c9-7808b14cb6b5
Microsoft Windows Server 2008 for 32-bit Systems 0
-
Microsoft Security Update for Windows Server 2008 (KB975517)
http://www.microsoft.com/downloads/details.aspx?familyid=ff6bfcf3-76c9 -4c45-b57d-22f94458dd6e
Microsoft Windows Vista x64 Edition SP1
-
Microsoft Security Update for Windows Vista for x64-based Systems (KB975517)
http://www.microsoft.com/downloads/details.aspx?familyid=62ed5d0a-5ca6 -4942-80c9-7808b14cb6b5
References
Microsoft Windows SMB2 '_Smb2ValidateProviderCallback()' Remote Code Execution Vulnerability
References:
References:
- Acerca del BSOD de srv2.sys (Ruben Santamarta)
- Microsoft Security Advisory (975497) Vulnerabilities in SMB Could Allow Remote C (Microsoft)
- Microsoft Security Advisory 975497 Released (Microsoft)
- Microsoft Windows 7 Homepage (Microsoft)
- More explication on CVE-2009-3103 (Laurent Gaffie)
- MS09-050: Exploit timeline for the SMB2 RCE vulnerability (Microsoft)
- Regarding SMB2.0 Negotiate BSOD published by Laurent Gaffié (Rubén)
- SMB2: 351 Packets from the Trampoline (Piotr Bania)
- Update on the SMB vulnerability situation (Microsoft)
- Windows Vista Homepage (Microsoft)
- Windows Vista/7 : SMB2.0 NEGOTIATE PROTOCOL REQUEST Remote B.S.O.D. (Laurent Gaffié)
- Regarding Microsoft srv2.sys SMB2.0 NEGOTIATE BSOD (Reversemode
) - SMB SRV2.SYS Denial of Service PoC ([email protected])
- Microsoft Security Bulletin MS09-050 (Microsoft)
- Vulnerability Note VU#135940 Windows SMB version 2 vulnerability (US-CERT)