Microsoft Windows SChannel TLSv1 Remote Denial of Service Vulnerability
BID:43780
Info
Microsoft Windows SChannel TLSv1 Remote Denial of Service Vulnerability
| Bugtraq ID: | 43780 |
| Class: | Unknown |
| CVE: |
CVE-2010-3229 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 12 2010 12:00AM |
| Updated: | Oct 19 2010 11:49AM |
| Credit: | The Mu Test Suite Team |
| Vulnerable: |
Microsoft Windows Vista x64 Edition SP2 Microsoft Windows Vista x64 Edition SP1 Microsoft Windows Vista Ultimate 64-bit edition SP2 Microsoft Windows Vista Ultimate 64-bit edition SP1 Microsoft Windows Vista Home Premium 64-bit edition SP2 Microsoft Windows Vista Home Premium 64-bit edition SP1 Microsoft Windows Vista Home Basic 64-bit edition SP2 Microsoft Windows Vista Home Basic 64-bit edition SP1 Microsoft Windows Vista Enterprise 64-bit edition SP2 Microsoft Windows Vista Enterprise 64-bit edition SP1 Microsoft Windows Vista Business 64-bit edition SP2 Microsoft Windows Vista Business 64-bit edition SP1 Microsoft Windows Vista Ultimate SP2 Microsoft Windows Vista Ultimate SP1 Microsoft Windows Vista SP2 Microsoft Windows Vista SP1 Microsoft Windows Vista Home Premium SP2 Microsoft Windows Vista Home Premium SP1 Microsoft Windows Vista Home Basic SP2 Microsoft Windows Vista Home Basic SP1 Microsoft Windows Vista Enterprise SP2 Microsoft Windows Vista Enterprise SP1 Microsoft Windows Vista Business SP2 Microsoft Windows Vista Business SP1 Microsoft Windows Server 2008 Standard Edition X64 Microsoft Windows Server 2008 Standard Edition SP2 Microsoft Windows Server 2008 Standard Edition Itanium Microsoft Windows Server 2008 Standard Edition 0 Microsoft Windows Server 2008 Standard Edition - Sp2 Web Microsoft Windows Server 2008 Standard Edition - Sp2 Storage Microsoft Windows Server 2008 Standard Edition - Sp2 Hpc Microsoft Windows Server 2008 Standard Edition - Gold Web Microsoft Windows Server 2008 Standard Edition - Gold Storage Microsoft Windows Server 2008 Standard Edition - Gold Standard Microsoft Windows Server 2008 Standard Edition - Gold Itanium Microsoft Windows Server 2008 Standard Edition - Gold Hpc Microsoft Windows Server 2008 Standard Edition - Gold Enterprise Microsoft Windows Server 2008 Standard Edition - Gold Datacenter Microsoft Windows Server 2008 Standard Edition - Gold Microsoft Windows Server 2008 for x64-based Systems SP2 Microsoft Windows Server 2008 for x64-based Systems R2 Microsoft Windows Server 2008 for x64-based Systems 0 Microsoft Windows Server 2008 for Itanium-based Systems SP2 Microsoft Windows Server 2008 for Itanium-based Systems R2 Microsoft Windows Server 2008 for Itanium-based Systems 0 Microsoft Windows Server 2008 for 32-bit Systems SP2 Microsoft Windows Server 2008 for 32-bit Systems 0 Microsoft Windows Server 2008 Enterprise Edition SP2 Microsoft Windows Server 2008 Enterprise Edition 0 Microsoft Windows Server 2008 Datacenter Edition SP2 Microsoft Windows Server 2008 Datacenter Edition 0 Microsoft Windows Server 2008 SP2 Beta Microsoft Windows 7 XP Mode 0 Microsoft Windows 7 Ultimate 0 Microsoft Windows 7 Starter 0 Microsoft Windows 7 Professional 0 Microsoft Windows 7 Home Premium 0 Microsoft Windows 7 for x64-based Systems 0 Microsoft Windows 7 for 32-bit Systems 0 Avaya Aura Conferencing Standard Avaya Aura Conferencing 6.0 Standard |
| Not Vulnerable: | |
Discussion
Microsoft Windows SChannel TLSv1 Remote Denial of Service Vulnerability
Microsoft Windows is prone to a remote denial-of-service vulnerability that affects the Secure Channel (SChannel) security package.
Successful exploits will allow an attacker to crash the affected system, resulting in a system restart. Repeated attacks will cause a permanent denial-of-service condition.
Microsoft Windows is prone to a remote denial-of-service vulnerability that affects the Secure Channel (SChannel) security package.
Successful exploits will allow an attacker to crash the affected system, resulting in a system restart. Repeated attacks will cause a permanent denial-of-service condition.
Exploit / POC
Microsoft Windows SChannel TLSv1 Remote Denial of Service Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Windows SChannel TLSv1 Remote Denial of Service Vulnerability
Solution:
The vendor released an advisory and updates. Please see the references for details.
Microsoft Windows Vista SP1
Microsoft Windows Server 2008 for Itanium-based Systems SP2
Microsoft Windows 7 for x64-based Systems 0
Microsoft Windows Vista SP2
Microsoft Windows 7 for 32-bit Systems 0
Microsoft Windows Server 2008 for Itanium-based Systems R2
Microsoft Windows Server 2008 for Itanium-based Systems 0
Microsoft Windows Vista x64 Edition SP2
Microsoft Windows Vista x64 Edition SP1
Solution:
The vendor released an advisory and updates. Please see the references for details.
Microsoft Windows Vista SP1
-
Microsoft Windows6.0-KB2207566-x86.msu
http://www.microsoft.com/downloads/details.aspx?familyid=4AF2F6E6-6905 -498C-BFBA-A565976B3365
Microsoft Windows Server 2008 for Itanium-based Systems SP2
-
Microsoft Windows6.0-KB2207566-ia64.msu
http://www.microsoft.com/downloads/details.aspx?familyid=2FFF281A-2221 -42A3-A2B7-07B5C5E66AE7
Microsoft Windows 7 for x64-based Systems 0
-
Microsoft Windows6.1-KB2207566-x64.msu
http://www.microsoft.com/downloads/details.aspx?familyid=50D27C23-5F69 -40FA-B517-32C245009467
Microsoft Windows Vista SP2
-
Microsoft Windows6.0-KB2207566-x86.msu
http://www.microsoft.com/downloads/details.aspx?familyid=4AF2F6E6-6905 -498C-BFBA-A565976B3365
Microsoft Windows 7 for 32-bit Systems 0
-
Microsoft Windows6.1-KB2207566-x86.msu
http://www.microsoft.com/downloads/details.aspx?familyid=D7A08A66-08B4 -421C-AFAD-F2F367D4A9F0
Microsoft Windows Server 2008 for Itanium-based Systems R2
-
Microsoft Windows6.1-KB2207566-ia64.msu
http://www.microsoft.com/downloads/details.aspx?familyid=334D39E6-8E4C -4E83-94C1-1DB3D636E865
Microsoft Windows Server 2008 for Itanium-based Systems 0
-
Microsoft Windows6.0-KB2207566-ia64.msu
http://www.microsoft.com/downloads/details.aspx?familyid=2FFF281A-2221 -42A3-A2B7-07B5C5E66AE7
Microsoft Windows Vista x64 Edition SP2
-
Microsoft Windows6.0-KB2207566-x64.msu
http://www.microsoft.com/downloads/details.aspx?familyid=8C56BA29-B2A8 -47A8-A605-4C54C0A7FA7C
Microsoft Windows Vista x64 Edition SP1
-
Microsoft Windows6.0-KB2207566-x64.msu
http://www.microsoft.com/downloads/details.aspx?familyid=8C56BA29-B2A8 -47A8-A605-4C54C0A7FA7C
References
Microsoft Windows SChannel TLSv1 Remote Denial of Service Vulnerability
References:
References:
- Microsoft Homepage (Microsoft)
- ASA-2010-289 (2207566) (Avaya)
- Microsoft Security Bulletin MS10-085 (Microsoft)