Microsoft Active Directory Federation Services Header Validation Remote Code Execution Vulnerability
BID:37214
Info
Microsoft Active Directory Federation Services Header Validation Remote Code Execution Vulnerability
| Bugtraq ID: | 37214 |
| Class: | Design Error |
| CVE: |
CVE-2009-2509 |
| Remote: | Yes |
| Local: | No |
| Published: | Dec 08 2009 12:00AM |
| Updated: | Dec 09 2009 08:44PM |
| Credit: | Microsoft |
| Vulnerable: |
Microsoft Windows Server 2008 Standard Edition SP2 Microsoft Windows Server 2008 Standard Edition 0 Microsoft Windows Server 2008 R2 Datacenter 0 Microsoft Windows Server 2008 for x64-based Systems SP2 Microsoft Windows Server 2008 for x64-based Systems R2 Microsoft Windows Server 2008 for x64-based Systems 0 Microsoft Windows Server 2008 for 32-bit Systems SP2 Microsoft Windows Server 2008 for 32-bit Systems 0 Microsoft Windows Server 2008 Enterprise Edition SP2 Microsoft Windows Server 2008 Enterprise Edition 0 Microsoft Windows Server 2008 Datacenter Edition SP2 Microsoft Windows Server 2008 Datacenter Edition 0 Microsoft Windows Server 2008 SP2 Beta Microsoft Windows Server 2003 x64 SP2 Microsoft Windows Server 2003 x64 SP1 Microsoft Windows Server 2003 Web Edition SP2 Microsoft Windows Server 2003 Web Edition SP1 Microsoft Windows Server 2003 Web Edition Microsoft Windows Server 2003 Standard x64 Edition Microsoft Windows Server 2003 Standard Edition SP2 Microsoft Windows Server 2003 Standard Edition SP1 Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Enterprise x64 Edition SP2 Microsoft Windows Server 2003 Enterprise x64 Edition Microsoft Windows Server 2003 Enterprise Edition SP1 Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Datacenter x64 Edition SP2 Microsoft Windows Server 2003 Datacenter x64 Edition Microsoft Windows Server 2003 Datacenter Edition SP1 Microsoft Windows Server 2003 Datacenter Edition Microsoft Windows Server 2003 SP2 Microsoft Windows Server 2003 SP1 Microsoft Windows Server 2008 R2 |
| Not Vulnerable: | |
Discussion
Microsoft Active Directory Federation Services Header Validation Remote Code Execution Vulnerability
Microsoft Active Directory Federation Services (ADFS) is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the application, which may aid in further attacks.
Microsoft Active Directory Federation Services (ADFS) is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the application, which may aid in further attacks.
Exploit / POC
Microsoft Active Directory Federation Services Header Validation Remote Code Execution Vulnerability
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Active Directory Federation Services Header Validation Remote Code Execution Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft Windows Server 2008 for x64-based Systems 0
Microsoft Windows Server 2008 for 32-bit Systems SP2
Microsoft Windows Server 2003 SP2
Microsoft Windows Server 2003 Datacenter x64 Edition SP2
Microsoft Windows Server 2003 Standard Edition SP2
Microsoft Windows Server 2008 for x64-based Systems SP2
Microsoft Windows Server 2003 Web Edition SP2
Microsoft Windows Server 2008 for 32-bit Systems 0
Microsoft Windows Server 2003 x64 SP2
Microsoft Windows Server 2003 Enterprise x64 Edition SP2
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft Windows Server 2008 for x64-based Systems 0
-
Microsoft Security Update for Windows Server 2008 x64 Edition (KB971726)
http://www.microsoft.com/downloads/details.aspx?familyid=7d1f5e9e-a7de -4f96-89c8-510fd51f16e7
Microsoft Windows Server 2008 for 32-bit Systems SP2
-
Microsoft Security Update for Windows Server 2008 (KB971726)
http://www.microsoft.com/downloads/details.aspx?familyid=f6715abb-fd93 -44ba-9854-2ecc672622da
Microsoft Windows Server 2003 SP2
-
Microsoft Security Update for Windows Server 2003 (KB971726)
http://www.microsoft.com/downloads/details.aspx?familyid=31351b9e-b5bb -4618-990b-1089ea5a3bc2
Microsoft Windows Server 2003 Datacenter x64 Edition SP2
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB971726)
http://www.microsoft.com/downloads/details.aspx?familyid=b6eb9d9b-1a43 -4b30-a033-19a1db786244
Microsoft Windows Server 2003 Standard Edition SP2
-
Microsoft Security Update for Windows Server 2003 (KB971726)
http://www.microsoft.com/downloads/details.aspx?familyid=31351b9e-b5bb -4618-990b-1089ea5a3bc2
Microsoft Windows Server 2008 for x64-based Systems SP2
-
Microsoft Security Update for Windows Server 2008 x64 Edition (KB971726)
http://www.microsoft.com/downloads/details.aspx?familyid=7d1f5e9e-a7de -4f96-89c8-510fd51f16e7
Microsoft Windows Server 2003 Web Edition SP2
-
Microsoft Security Update for Windows Server 2003 (KB971726)
http://www.microsoft.com/downloads/details.aspx?familyid=31351b9e-b5bb -4618-990b-1089ea5a3bc2
Microsoft Windows Server 2008 for 32-bit Systems 0
-
Microsoft Security Update for Windows Server 2008 (KB971726)
http://www.microsoft.com/downloads/details.aspx?familyid=f6715abb-fd93 -44ba-9854-2ecc672622da
Microsoft Windows Server 2003 x64 SP2
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB971726)
http://www.microsoft.com/downloads/details.aspx?familyid=b6eb9d9b-1a43 -4b30-a033-19a1db786244
Microsoft Windows Server 2003 Enterprise x64 Edition SP2
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB971726)
http://www.microsoft.com/downloads/details.aspx?familyid=b6eb9d9b-1a43 -4b30-a033-19a1db786244
References
Microsoft Active Directory Federation Services Header Validation Remote Code Execution Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- Microsoft Security Bulletin MS09-070 (Microsoft)