Microsoft MSDTC Service Denial of Service Vulnerability
BID:4006
Info
Microsoft MSDTC Service Denial of Service Vulnerability
| Bugtraq ID: | 4006 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2002-0224 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 31 2002 12:00AM |
| Updated: | Jul 11 2009 09:56AM |
| Credit: | This vulnerability was reported by [email protected]. |
| Vulnerable: |
Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server Microsoft SQL Server 2000 SP2 Microsoft SQL Server 2000 SP1 Microsoft SQL Server 2000 Microsoft SQL Server 7.0 SP3 alpha Microsoft SQL Server 7.0 SP3 Microsoft SQL Server 7.0 SP2 alpha Microsoft SQL Server 7.0 SP2 Microsoft SQL Server 7.0 SP1 alpha Microsoft SQL Server 7.0 SP1 Microsoft SQL Server 7.0 alpha Microsoft SQL Server 7.0 Microsoft SQL Server 6.5 Microsoft IIS 5.0 |
| Not Vulnerable: | |
Discussion
Microsoft MSDTC Service Denial of Service Vulnerability
The Microsoft Distributed Transaction Service Coordinator (MSDTC) allows for ditributed transaction processing in a clustered or distributed environment. It is installed by default on Windows 2000, as well as with Microsoft SQL Server 6.5 and higher.
It has been reported that it is possible to cause this service to crash by sending 1024 bytes of random data to its listening port, by default port 3372.
Restarting the service will reportedly allow it to resume normal operation.
The existence of this vulnerability has not been confirmed by Microsoft.
* Further reports indicate that sending approximately 20200 null bytes to the service, will cause the entire system to become unresponsive.
The Microsoft Distributed Transaction Service Coordinator (MSDTC) allows for ditributed transaction processing in a clustered or distributed environment. It is installed by default on Windows 2000, as well as with Microsoft SQL Server 6.5 and higher.
It has been reported that it is possible to cause this service to crash by sending 1024 bytes of random data to its listening port, by default port 3372.
Restarting the service will reportedly allow it to resume normal operation.
The existence of this vulnerability has not been confirmed by Microsoft.
* Further reports indicate that sending approximately 20200 null bytes to the service, will cause the entire system to become unresponsive.
Exploit / POC
Microsoft MSDTC Service Denial of Service Vulnerability
No exploit code is necessary for this vulnerability.
No exploit code is necessary for this vulnerability.
Solution / Fix
Microsoft MSDTC Service Denial of Service Vulnerability
Solution:
A reliable source has indicated that the patches released in Microsoft Security Bulletin MS02-018 address this issue. However, this has not been confirmed, as this issue is not mentioned in the Microsoft bulletin.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
A reliable source has indicated that the patches released in Microsoft Security Bulletin MS02-018 address this issue. However, this has not been confirmed, as this issue is not mentioned in the Microsoft bulletin.
Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft MSDTC Service Denial of Service Vulnerability
References:
References:
- Microsoft Security Bulletin MS02-018 (Microsoft)