Microsoft SMTP Service Malformed Command Denial of Service Vulnerability
BID:4204
Info
Microsoft SMTP Service Malformed Command Denial of Service Vulnerability
| Bugtraq ID: | 4204 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 27 2002 12:00AM |
| Updated: | Feb 27 2002 12:00AM |
| Credit: | Discovery of this issue is credited to H D Moore. |
| Vulnerable: |
Microsoft Windows XP Professional Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server Microsoft Exchange Server 2000 SP2 Microsoft Exchange Server 2000 SP1 Microsoft Exchange Server 2000 |
| Not Vulnerable: | |
Discussion
Microsoft SMTP Service Malformed Command Denial of Service Vulnerability
It has been reported that the native Windows 2000 and XP Professional SMTP service encounters difficulties when attempting to handle certain types of malformed SMTP commands. A remote attacker may be able to exploit this condition to cause a denial of SMTP service. The vulnerable software must be restarted to regain normal functionality.
It has been reported that the native Windows 2000 and XP Professional SMTP service encounters difficulties when attempting to handle certain types of malformed SMTP commands. A remote attacker may be able to exploit this condition to cause a denial of SMTP service. The vulnerable software must be restarted to regain normal functionality.
Exploit / POC
Microsoft SMTP Service Malformed Command Denial of Service Vulnerability
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft SMTP Service Malformed Command Denial of Service Vulnerability
Solution:
Microsoft has released fixes which address this vulnerability. Furthermore, these fixes will be included in Windows 2000 Service Pack 3 and Windows XP Professional Service Pack 1.
Microsoft Windows 2000 Server SP2
Microsoft Windows 2000 Advanced Server SP2
Microsoft Windows XP Professional
Microsoft Windows 2000 Professional SP2
Solution:
Microsoft has released fixes which address this vulnerability. Furthermore, these fixes will be included in Windows 2000 Service Pack 3 and Windows XP Professional Service Pack 1.
Microsoft Windows 2000 Server SP2
-
Microsoft Q313450_W2K_SP3_X86_EN.exe
This fix may only be applied to Microsoft Windows 2000 systems running Service Pack 2.
http://download.microsoft.com/download/win2000platform/Patch/Q313450/N T5/EN-US/Q313450_W2K_SP3_X86_EN.exe
Microsoft Windows 2000 Advanced Server SP2
-
Microsoft Q313450_W2K_SP3_X86_EN.exe
This fix may only be applied to Microsoft Windows 2000 systems running Service Pack 2.
http://download.microsoft.com/download/win2000platform/Patch/Q313450/N T5/EN-US/Q313450_W2K_SP3_X86_EN.exe
Microsoft Windows XP Professional
-
Microsoft Q313450_WXP_SP1_x86_ENU.exe
This patch may be applied to systems running Windows XP Professional Gold.
http://download.microsoft.com/download/whistler/Patch/Q313450/WXP/EN-U S/Q313450_WXP_SP1_x86_ENU.exe
Microsoft Windows 2000 Professional SP2
-
Microsoft Q313450_W2K_SP3_X86_EN.exe
This fix may only be applied to Microsoft Windows 2000 systems running Service Pack 2.
http://download.microsoft.com/download/win2000platform/Patch/Q313450/N T5/EN-US/Q313450_W2K_SP3_X86_EN.exe
References
Microsoft SMTP Service Malformed Command Denial of Service Vulnerability
References:
References:
- IIS SMTP BDAT DoS (CORE Security)
- Microsoft Security Bulletin MS01-012 Malformed Data Transfer Request (Microsoft )
- Technet Security (Microsoft)