Microsoft Windows SMTP Service Authorization Bypass Vulnerability
BID:4205
Info
Microsoft Windows SMTP Service Authorization Bypass Vulnerability
| Bugtraq ID: | 4205 |
| Class: | Access Validation Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 27 2002 12:00AM |
| Updated: | Feb 27 2002 12:00AM |
| Credit: | Discovery is credited to Bindview's RAZOR Team. |
| Vulnerable: |
Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server Microsoft Exchange Server 5.5 SP4 Microsoft Exchange Server 5.5 SP3 Microsoft Exchange Server 5.5 SP2 Microsoft Exchange Server 5.5 SP1 Microsoft Exchange Server 5.5 Microsoft Exchange Server 5.0 SP2 Microsoft Exchange Server 5.0 SP1 Microsoft Exchange Server 5.0 |
| Not Vulnerable: | |
Discussion
Microsoft Windows SMTP Service Authorization Bypass Vulnerability
A vulnerability has been reported in the Microsoft Windows 2000 SMTP service and Microsoft Exchange Server Internet Mail Connector service. This issue may allow an attacker to gain unauthorized user-level access to the SMTP service on a vulnerable host.
The consequences of this issue are that an attacker may potentially exploit this vulnerability to turn the server into a mail relay.
Systems running Microsoft Exchange 2000 are not prone to this issue.
** The advisory on this issue released by the BindView RAZOR team states that a user connecting through a NULL session can also exploit this vulnerability. Support for NULL sessions is enabled by default. This enables anonymous users who have not authenticated through NTLM to use the server as a mail relay.
A vulnerability has been reported in the Microsoft Windows 2000 SMTP service and Microsoft Exchange Server Internet Mail Connector service. This issue may allow an attacker to gain unauthorized user-level access to the SMTP service on a vulnerable host.
The consequences of this issue are that an attacker may potentially exploit this vulnerability to turn the server into a mail relay.
Systems running Microsoft Exchange 2000 are not prone to this issue.
** The advisory on this issue released by the BindView RAZOR team states that a user connecting through a NULL session can also exploit this vulnerability. Support for NULL sessions is enabled by default. This enables anonymous users who have not authenticated through NTLM to use the server as a mail relay.
Exploit / POC
Microsoft Windows SMTP Service Authorization Bypass Vulnerability
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently the SecurityFocus staff are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Windows SMTP Service Authorization Bypass Vulnerability
Solution:
Microsoft has released fixes which address this issue. The fix for Microsoft Windows 2000 will be incorporated in Service Pack 3.
Microsoft has released an updated advisory MS02-011 dealing with this issue. The updated advisory contains fixes for the Exchange Server. Please see the referenced updated advisory for more information and details on obtaining fixes.
Microsoft Exchange Server 5.0 SP2
Microsoft Windows 2000 Server SP2
Microsoft Windows 2000 Advanced Server SP2
Microsoft Exchange Server 5.5 SP4
Microsoft Windows 2000 Professional SP2
Solution:
Microsoft has released fixes which address this issue. The fix for Microsoft Windows 2000 will be incorporated in Service Pack 3.
Microsoft has released an updated advisory MS02-011 dealing with this issue. The updated advisory contains fixes for the Exchange Server. Please see the referenced updated advisory for more information and details on obtaining fixes.
Microsoft Exchange Server 5.0 SP2
-
Microsoft Security Update for Exchange 5.0 (KB834130)
http://www.microsoft.com/downloads/details.aspx?FamilyId=164610A4-AAFC -40AC-85CA-349DBDBE1731&displaylang=en
Microsoft Windows 2000 Server SP2
-
Microsoft Q313450_W2K_SP3_X86_EN.exe
This fix may only be applied to Microsoft Windows 2000 systems running Service Pack 2.
http://download.microsoft.com/download/win2000platform/Patch/Q313450/N T5/EN-US/Q313450_W2K_SP3_X86_EN.exe
Microsoft Windows 2000 Advanced Server SP2
-
Microsoft Q313450_W2K_SP3_X86_EN.exe
This fix may only be applied to Microsoft Windows 2000 systems running Service Pack 2.
http://download.microsoft.com/download/win2000platform/Patch/Q313450/N T5/EN-US/Q313450_W2K_SP3_X86_EN.exe
Microsoft Exchange Server 5.5 SP4
-
Microsoft Q289258engi386.EXE
This fix may be applied to systems running Microsoft Exchange Server 5.5 Service Pack 4.
http://download.microsoft.com/download/exch55/Patch/05.05.55.2655/NT45 /EN-US/Q289258engi386.EXE
Microsoft Windows 2000 Professional SP2
-
Microsoft Q313450_W2K_SP3_X86_EN.exe
This fix may only be applied to Microsoft Windows 2000 systems running Service Pack 2.
http://download.microsoft.com/download/win2000platform/Patch/Q313450/N T5/EN-US/Q313450_W2K_SP3_X86_EN.exe
References
Microsoft Windows SMTP Service Authorization Bypass Vulnerability
References:
References:
- Microsoft Security Bulletin MS02-011 (Microsoft)
- RestrictAnonymous: Enumeration and the Null User (SecurityFocus)
- Technet Security (Microsoft)
- UPDATED: Microsoft Security Bulletin MS02-011 (Microsoft)