Microsoft Windows License Logging Server Remote Heap Buffer Overflow Vulnerability
BID:36921
Info
Microsoft Windows License Logging Server Remote Heap Buffer Overflow Vulnerability
| Bugtraq ID: | 36921 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2009-2523 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 10 2009 12:00AM |
| Updated: | Nov 16 2009 03:46PM |
| Credit: | Cody Pierce working with the Zero Day Initiative |
| Vulnerable: |
Nortel Networks Enterprise VoIP TM-CS1000 Nortel Networks Contact Center Express Nortel Networks Contact Center - TAPI Server 0 Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: |
Microsoft Windows 2000 Professional SP4 |
Discussion
Microsoft Windows License Logging Server Remote Heap Buffer Overflow Vulnerability
The Microsoft Windows License Logging Server is prone to a remote heap-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successful exploits will completely compromise affected computers. Failed exploit attempts will result in a denial-of-service condition.
The Microsoft Windows License Logging Server is prone to a remote heap-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
An attacker can exploit this issue to execute arbitrary code with SYSTEM-level privileges. Successful exploits will completely compromise affected computers. Failed exploit attempts will result in a denial-of-service condition.
Exploit / POC
Microsoft Windows License Logging Server Remote Heap Buffer Overflow Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
A commercial proof of concept is available through VUPEN Security - Exploit and PoCs Service. This proof of concept is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft Windows License Logging Server Remote Heap Buffer Overflow Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft Windows 2000 Advanced Server SP4
Microsoft Windows 2000 Server SP4
Microsoft Windows 2000 Datacenter Server SP4
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft Windows 2000 Advanced Server SP4
-
Microsoft Security Update for Windows 2000 (KB974783)
http://www.microsoft.com/downloads/details.aspx?familyid=365a8dff-2383 -42f6-b567-e545461fd135
Microsoft Windows 2000 Server SP4
-
Microsoft Security Update for Windows 2000 (KB974783)
http://www.microsoft.com/downloads/details.aspx?familyid=365a8dff-2383 -42f6-b567-e545461fd135
Microsoft Windows 2000 Datacenter Server SP4
-
Microsoft Security Update for Windows 2000 (KB974783)
http://www.microsoft.com/downloads/details.aspx?familyid=365a8dff-2383 -42f6-b567-e545461fd135
References
Microsoft Windows License Logging Server Remote Heap Buffer Overflow Vulnerability
References:
References:
- Nortel Enterprise Response to Microsoft Security Bulletin MS09-064 (Nortel Networks)
- Microsoft Homepage (Microsoft)
- TPTI-09-07: Microsoft Windows License Logging Service Heap Corruption Vulnerabil (dvlabs
) - Details on the License Logging Service vulnerability (Microsoft Security Research & Defense)
- Microsoft Security Bulletin MS09-064 (Microsoft)
- Microsoft Windows License Logging Service Heap Corruption Vulnerability (dvlabs
)