Microsoft Windows 2000 Remote Access Service Buffer Overflow Vulnerability
BID:4852
Info
Microsoft Windows 2000 Remote Access Service Buffer Overflow Vulnerability
| Bugtraq ID: | 4852 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | May 27 2002 12:00AM |
| Updated: | May 27 2002 12:00AM |
| Credit: | Vulnerability discovery credited to Next Generation Security Software. |
| Vulnerable: |
Microsoft Windows XP Professional Microsoft Windows XP Home Microsoft Windows XP 64-bit Edition Microsoft Windows NT Workstation 4.0 SP6a Microsoft Windows NT Workstation 4.0 SP6 Microsoft Windows NT Workstation 4.0 SP5 Microsoft Windows NT Workstation 4.0 SP4 Microsoft Windows NT Workstation 4.0 SP3 Microsoft Windows NT Workstation 4.0 SP2 Microsoft Windows NT Workstation 4.0 SP1 Microsoft Windows NT Workstation 4.0 Microsoft Windows NT Terminal Server 4.0 SP6 Microsoft Windows NT Terminal Server 4.0 SP5 Microsoft Windows NT Terminal Server 4.0 SP4 Microsoft Windows NT Terminal Server 4.0 SP3 Microsoft Windows NT Terminal Server 4.0 SP2 Microsoft Windows NT Terminal Server 4.0 SP1 Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6 Microsoft Windows NT Enterprise Server 4.0 SP5 Microsoft Windows NT Enterprise Server 4.0 SP4 Microsoft Windows NT Enterprise Server 4.0 SP3 Microsoft Windows NT Enterprise Server 4.0 SP2 Microsoft Windows NT Enterprise Server 4.0 SP1 Microsoft Windows NT Enterprise Server 4.0 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Discussion
Microsoft Windows 2000 Remote Access Service Buffer Overflow Vulnerability
Remote Access Service (RAS) is a service included in Microsoft Windows 2000, NT 4.0 and XP to allow users to connect to a corporate intranet or the Internet from a remote computer.
The RAS service included with several versions of Microsoft Windows is vulnerable to a buffer overflow issue. This may be exploited by a local attacker by creating a malicious phonebook entry. It is possible to gain elevated privileges, or create a denial of service condition.
** It has been reported that the Microsoft supplied patch to correct this issue may cause problems with PPTP RAS connections on Windows 2000 Professional. This problem has not been confirmed by SecurityFocus at this time. Microsoft also has not yet publicly acknowledged that this problem occurs.
** Microsoft has now released an updated patch version that correctly handles VPN connections.
Remote Access Service (RAS) is a service included in Microsoft Windows 2000, NT 4.0 and XP to allow users to connect to a corporate intranet or the Internet from a remote computer.
The RAS service included with several versions of Microsoft Windows is vulnerable to a buffer overflow issue. This may be exploited by a local attacker by creating a malicious phonebook entry. It is possible to gain elevated privileges, or create a denial of service condition.
** It has been reported that the Microsoft supplied patch to correct this issue may cause problems with PPTP RAS connections on Windows 2000 Professional. This problem has not been confirmed by SecurityFocus at this time. Microsoft also has not yet publicly acknowledged that this problem occurs.
** Microsoft has now released an updated patch version that correctly handles VPN connections.
Solution / Fix
Microsoft Windows 2000 Remote Access Service Buffer Overflow Vulnerability
Solution:
Microsoft has released patches to address this issue:
Microsoft Windows 2000 Server SP2
Microsoft Windows 2000 Advanced Server SP2
Microsoft Windows NT Workstation 4.0 SP6a
Microsoft Windows NT Server 4.0 SP6a
Microsoft Windows 2000 Professional SP2
Microsoft Windows XP Home
Microsoft Windows XP 64-bit Edition
Microsoft Windows NT Enterprise Server 4.0 SP6a
Microsoft Windows 2000 Datacenter Server SP2
Microsoft Windows XP Professional
Solution:
Microsoft has released patches to address this issue:
Microsoft Windows 2000 Server SP2
-
Microsoft Q318138
For Windows 2000.
http://www.microsoft.com/windows2000/downloads/security/q318138/defaul t.asp
Microsoft Windows 2000 Advanced Server SP2
-
Microsoft Q318138
For Windows 2000.
http://www.microsoft.com/windows2000/downloads/security/q318138/defaul t.asp
Microsoft Windows NT Workstation 4.0 SP6a
-
Microsoft Q318138
For NT 4.0 running RRAS.
http://www.microsoft.com/ntserver/nts/downloads/security/q318138/defau lt.asp -
Microsoft Q318138
For Windows NT 4.0.
http://www.microsoft.com/ntserver/nts/downloads/security/q318138/defau lt.asp
Microsoft Windows NT Server 4.0 SP6a
-
Microsoft Q318138
For NT 4.0 running RRAS.
http://www.microsoft.com/ntserver/nts/downloads/security/q318138/defau lt.asp -
Microsoft Q318138
For Windows NT 4.0.
http://www.microsoft.com/ntserver/nts/downloads/security/q318138/defau lt.asp
Microsoft Windows 2000 Professional SP2
-
Microsoft Q318138
For Windows 2000.
http://www.microsoft.com/windows2000/downloads/security/q318138/defaul t.asp
Microsoft Windows XP Home
-
Microsoft Q318138
For Windows XP.
http://www.microsoft.com/downloads/release.asp?ReleaseID=38833
Microsoft Windows XP 64-bit Edition
-
Microsoft Q318138
For Windows XP 64-bit Edition.
http://www.microsoft.com/downloads/release.asp?ReleaseID=39011
Microsoft Windows NT Enterprise Server 4.0 SP6a
-
Microsoft Q318138
For NT 4.0 running RRAS.
http://www.microsoft.com/ntserver/nts/downloads/security/q318138/defau lt.asp -
Microsoft Q318138
For Windows NT 4.0.
http://www.microsoft.com/ntserver/nts/downloads/security/q318138/defau lt.asp
Microsoft Windows 2000 Datacenter Server SP2
-
Microsoft Q318138
For Windows 2000.
http://www.microsoft.com/windows2000/downloads/security/q318138/defaul t.asp
Microsoft Windows XP Professional
-
Microsoft Q318138
For Windows XP.
http://www.microsoft.com/downloads/release.asp?ReleaseID=38833