Microsoft Windows Media Service Transport Information Packet Stack Buffer Overflow Vulnerability
BID:39356
Info
Microsoft Windows Media Service Transport Information Packet Stack Buffer Overflow Vulnerability
| Bugtraq ID: | 39356 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-0478 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 13 2010 12:00AM |
| Updated: | Jun 01 2010 12:50PM |
| Credit: | Fabien Perigaud of CERT-LEXSI |
| Vulnerable: |
Nortel Networks Self-Service Speech Server 0 Nortel Networks Self-Service Peri Application 0 Nortel Networks Self-Service MPS 500 0 Nortel Networks Self-Service MPS 1000 0 Nortel Networks Self-Service Media Processing Server 0 Nortel Networks Self Service - CDD 0 Nortel Networks ENSM Visualization Performance Fault Manager VPFM 0 Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Discussion
Microsoft Windows Media Service Transport Information Packet Stack Buffer Overflow Vulnerability
Microsoft Windows Media Service is prone to a remote stack-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Update (April 21, 2010): Microsoft reports that the patch released as MS10-025 does not resolve this issue. Microsoft intends to release a new fix in the following week; this BID will be updated as more information emerges.
Update (April 27, 2010): Updated MS10-025 includes a new fix.
Microsoft Windows Media Service is prone to a remote stack-based buffer-overflow vulnerability because the application fails to perform adequate boundary checks on user-supplied data.
Attackers can exploit this issue to execute arbitrary code within the context of the affected application. Failed exploit attempts will result in a denial-of-service condition.
Update (April 21, 2010): Microsoft reports that the patch released as MS10-025 does not resolve this issue. Microsoft intends to release a new fix in the following week; this BID will be updated as more information emerges.
Update (April 27, 2010): Updated MS10-025 includes a new fix.
Exploit / POC
Microsoft Windows Media Service Transport Information Packet Stack Buffer Overflow Vulnerability
Symantec detected that this issue is being actively exploited in the wild.
A commercial exploit is available through the Immunity Partners program. The exploit was released as part of Immunity's CANVAS Early Update service and is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Symantec detected that this issue is being actively exploited in the wild.
A commercial exploit is available through the Immunity Partners program. The exploit was released as part of Immunity's CANVAS Early Update service and is not otherwise publicly available or known to be circulating in the wild.
The following exploit code is available:
Solution / Fix
Microsoft Windows Media Service Transport Information Packet Stack Buffer Overflow Vulnerability
Solution:
The vendor has re-released an advisory and updates. Please see the references for details.
Microsoft Windows 2000 Advanced Server SP4
Microsoft Windows 2000 Professional SP4
Microsoft Windows 2000 Datacenter Server SP4
Solution:
The vendor has re-released an advisory and updates. Please see the references for details.
Microsoft Windows 2000 Advanced Server SP4
-
Microsoft Security Update for Windows Media Services 4.1 for Windows 2000 (KB980858)
http://www.microsoft.com/downloads/details.aspx?familyid=73B3D681-26BB -49C1-849E-1F72484CB978
Microsoft Windows 2000 Professional SP4
-
Microsoft Security Update for Windows Media Services 4.1 for Windows 2000 (KB980858)
http://www.microsoft.com/downloads/details.aspx?familyid=73B3D681-26BB -49C1-849E-1F72484CB978
Microsoft Windows 2000 Datacenter Server SP4
-
Microsoft Security Update for Windows Media Services 4.1 for Windows 2000 (KB980858)
http://www.microsoft.com/downloads/details.aspx?familyid=73B3D681-26BB -49C1-849E-1F72484CB978
References
Microsoft Windows Media Service Transport Information Packet Stack Buffer Overflow Vulnerability
References:
References:
- Cert-Lexsi - Microsoft Windows Media Services MMS Buffer Overflow Vulnerability (Cert-Lexsi)
- Microsoft Homepage (Microsoft)
- MS10-025 Re-Release Ready (Microsoft Security Response Center)
- MS10-025 Security Update to be Re-released (Jerry Bryant )
- Update on MS10-025 (Microsoft)
- Cert-Lexsi - Microsoft Windows Media Services MMS Buffer Overflow Vulnerability (Fabien PERIGAUD
) - Avaya Enterprise (Formerly Nortel Enterprise) Response to Microsoft Security Bul (Avaya)
- Microsoft Security Bulletin MS10-025 (Microsoft)