Microsoft Windows SMTP Server Insufficient Query ID Randomization DNS Spoofing Vulnerability
BID:39908
Info
Microsoft Windows SMTP Server Insufficient Query ID Randomization DNS Spoofing Vulnerability
| Bugtraq ID: | 39908 |
| Class: | Design Error |
| CVE: |
CVE-2010-1689 |
| Remote: | Yes |
| Local: | No |
| Published: | May 04 2010 12:00AM |
| Updated: | May 04 2010 12:00AM |
| Credit: | Nicolas Economou |
| Vulnerable: |
Microsoft Windows Server 2008 Standard Edition SP2 Microsoft Windows Server 2008 Standard Edition 0 Microsoft Windows Server 2008 R2 Datacenter 0 Microsoft Windows Server 2008 for x64-based Systems SP2 Microsoft Windows Server 2008 for x64-based Systems R2 Microsoft Windows Server 2008 for x64-based Systems 0 Microsoft Windows Server 2008 for Itanium-based Systems SP2 Microsoft Windows Server 2008 for Itanium-based Systems R2 Microsoft Windows Server 2008 for Itanium-based Systems 0 Microsoft Windows Server 2008 for 32-bit Systems SP2 Microsoft Windows Server 2008 for 32-bit Systems 0 Microsoft Windows Server 2008 Enterprise Edition SP2 Microsoft Windows Server 2008 Enterprise Edition 0 Microsoft Windows Server 2008 Datacenter Edition SP2 Microsoft Windows Server 2008 Datacenter Edition 0 Microsoft Windows Server 2008 SP2 Beta Microsoft Windows Server 2003 x64 SP2 Microsoft Windows Server 2003 x64 SP1 Microsoft Windows Server 2003 Web Edition SP2 Microsoft Windows Server 2003 Web Edition SP1 Microsoft Windows Server 2003 Web Edition Microsoft Windows Server 2003 Standard Edition SP2 Microsoft Windows Server 2003 Standard Edition SP1 Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Enterprise x64 Edition Microsoft Windows Server 2003 Enterprise Edition Itanium SP1 Beta 1 Microsoft Windows Server 2003 Enterprise Edition Itanium SP1 Microsoft Windows Server 2003 Enterprise Edition Itanium 0 Microsoft Windows Server 2003 Enterprise Edition SP1 Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Datacenter x64 Edition SP2 Microsoft Windows Server 2003 Datacenter x64 Edition Microsoft Windows Server 2003 Datacenter Edition Itanium SP1 Beta 1 Microsoft Windows Server 2003 Datacenter Edition Itanium SP1 Microsoft Windows Server 2003 Datacenter Edition Itanium 0 Microsoft Windows Server 2003 Datacenter Edition SP1 Microsoft Windows Server 2003 Datacenter Edition Microsoft Windows Server 2003 SP2 Microsoft Windows Server 2003 SP1 Microsoft Windows Server 2008 R2 Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server Microsoft Exchange Server 2010 x64 0 Microsoft Exchange Server 2007 x64 SP2 Microsoft Exchange Server 2007 x64 SP1 Microsoft Exchange Server 2007 x64 0 Microsoft Exchange Server 2007 SP2 Microsoft Exchange Server 2007 SP 1 Microsoft Exchange Server 2007 0 Microsoft Exchange Server 2003 SP2 Microsoft Exchange Server 2003 SP1 Microsoft Exchange Server 2003 |
| Not Vulnerable: | |
Discussion
Microsoft Windows SMTP Server Insufficient Query ID Randomization DNS Spoofing Vulnerability
The Microsoft Windows Simple Mail Transfer Protocol (SMTP) Server is prone to a DNS spoofing vulnerability.
Successfully exploiting this issue allows remote attackers to spoof DNS replies, allowing them to redirect network traffic and to launch man-in-the-middle attacks.
The Microsoft Windows Simple Mail Transfer Protocol (SMTP) Server is prone to a DNS spoofing vulnerability.
Successfully exploiting this issue allows remote attackers to spoof DNS replies, allowing them to redirect network traffic and to launch man-in-the-middle attacks.
Exploit / POC
Microsoft Windows SMTP Server Insufficient Query ID Randomization DNS Spoofing Vulnerability
An attacker can use standard tools to exploit this issue.
An attacker can use standard tools to exploit this issue.
Solution / Fix
Microsoft Windows SMTP Server Insufficient Query ID Randomization DNS Spoofing Vulnerability
Solution:
This issue is reported to be patched in Microsoft security advisory MS10-024; please see the references for more information.
Microsoft Windows Server 2008 for x64-based Systems 0
Microsoft Windows 2000 Advanced Server SP4
Microsoft Windows Server 2008 for 32-bit Systems SP2
Microsoft Windows Server 2003 SP2
Microsoft Windows Server 2008 for x64-based Systems R2
Microsoft Windows Server 2003 Datacenter x64 Edition SP2
Microsoft Windows Server 2003 Standard Edition SP2
Microsoft Windows Server 2008 for x64-based Systems SP2
Microsoft Windows 2000 Datacenter Server SP4
Microsoft Windows Server 2003 Web Edition SP2
Microsoft Windows Server 2008 for 32-bit Systems 0
Microsoft Windows Server 2003 x64 SP2
Microsoft Windows 2000 Professional SP4
Microsoft Exchange Server 2003 SP2
Solution:
This issue is reported to be patched in Microsoft security advisory MS10-024; please see the references for more information.
Microsoft Windows Server 2008 for x64-based Systems 0
-
Microsoft Security Update for Windows Server 2008 x64 Edition (KB976323)
http://www.microsoft.com/downloads/details.aspx?familyid=8F922E64-E3A6 -46FE-9A81-B2813EA6A330
Microsoft Windows 2000 Advanced Server SP4
-
Microsoft Security Update for Windows 2000 (KB976323)
http://www.microsoft.com/downloads/details.aspx?familyid=88A0E872-01DE -495B-8EEC-D105A970DAA7
Microsoft Windows Server 2008 for 32-bit Systems SP2
-
Microsoft Security Update for Windows Server 2008 (KB976323)
http://www.microsoft.com/downloads/details.aspx?familyid=E29EAD69-000A -4982-A25C-F3981EDA381A
Microsoft Windows Server 2003 SP2
-
Microsoft Security Update for Windows Server 2003 (KB976323)
http://www.microsoft.com/downloads/details.aspx?familyid=F781E9E4-87D4 -4243-9D44-256424D75FEC
Microsoft Windows Server 2008 for x64-based Systems R2
-
Microsoft Security Update for Windows Server 2008 R2 x64 Edition (KB976323)
http://www.microsoft.com/downloads/details.aspx?familyid=EB27CD2B-D514 -4405-8650-259A42E35155
Microsoft Windows Server 2003 Datacenter x64 Edition SP2
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB976323)
http://www.microsoft.com/downloads/details.aspx?familyid=644FF070-237B -4A73-B2E2-9FFFDAFA3927
Microsoft Windows Server 2003 Standard Edition SP2
-
Microsoft Security Update for Windows Server 2003 (KB976323)
http://www.microsoft.com/downloads/details.aspx?familyid=F781E9E4-87D4 -4243-9D44-256424D75FEC
Microsoft Windows Server 2008 for x64-based Systems SP2
-
Microsoft Security Update for Windows Server 2008 x64 Edition (KB976323)
http://www.microsoft.com/downloads/details.aspx?familyid=8F922E64-E3A6 -46FE-9A81-B2813EA6A330
Microsoft Windows 2000 Datacenter Server SP4
-
Microsoft Security Update for Windows 2000 (KB976323)
http://www.microsoft.com/downloads/details.aspx?familyid=88A0E872-01DE -495B-8EEC-D105A970DAA7
Microsoft Windows Server 2003 Web Edition SP2
-
Microsoft Security Update for Windows Server 2003 (KB976323)
http://www.microsoft.com/downloads/details.aspx?familyid=F781E9E4-87D4 -4243-9D44-256424D75FEC
Microsoft Windows Server 2008 for 32-bit Systems 0
-
Microsoft Security Update for Windows Server 2008 (KB976323)
http://www.microsoft.com/downloads/details.aspx?familyid=E29EAD69-000A -4982-A25C-F3981EDA381A
Microsoft Windows Server 2003 x64 SP2
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB976323)
http://www.microsoft.com/downloads/details.aspx?familyid=644FF070-237B -4A73-B2E2-9FFFDAFA3927
Microsoft Windows 2000 Professional SP4
-
Microsoft Security Update for Windows 2000 (KB976323)
http://www.microsoft.com/downloads/details.aspx?familyid=88A0E872-01DE -495B-8EEC-D105A970DAA7
Microsoft Exchange Server 2003 SP2
-
Microsoft Security Update for Exchange Server 2003 Service Pack 2 (KB976702)
http://www.microsoft.com/downloads/details.aspx?familyid=bc8391f8-5335 -496b-ad4c-bae38509be4a
References
Microsoft Windows SMTP Server Insufficient Query ID Randomization DNS Spoofing Vulnerability
References:
References:
- [CORE-2010-0427] Windows SMTP Service DNS query Id vulnerabilities (Core Security Technologies Advisories)
- Microsoft Homepage (Microsoft)
- Windows SMTP Service DNS query Id vulnerabilities (Core Security Technologies)
- Microsoft Security Bulletin MS10-024 (Microsoft)