Microsoft Windows WINS Server 'ECommEndDlg()' Local Privilege Escalation Vulnerability
BID:49523
Info
Microsoft Windows WINS Server 'ECommEndDlg()' Local Privilege Escalation Vulnerability
| Bugtraq ID: | 49523 |
| Class: | Unknown |
| CVE: |
CVE-2011-1984 |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 12 2011 12:00AM |
| Updated: | Sep 14 2011 11:01PM |
| Credit: | Nicolas Economou of Core Security. |
| Vulnerable: |
Microsoft Windows Server 2008 Standard Edition SP2 Microsoft Windows Server 2008 Standard Edition R2 SP1 Microsoft Windows Server 2008 Standard Edition R2 Microsoft Windows Server 2008 Standard Edition Itanium Microsoft Windows Server 2008 R2 x64 SP1 Microsoft Windows Server 2008 R2 x64 0 Microsoft Windows Server 2008 for x64-based Systems SP2 Microsoft Windows Server 2008 for x64-based Systems R2 Microsoft Windows Server 2008 for x64-based Systems 0 Microsoft Windows Server 2008 for Itanium-based Systems 0 Microsoft Windows Server 2008 for 32-bit Systems SP2 Microsoft Windows Server 2008 for 32-bit Systems 0 Microsoft Windows Server 2008 Enterprise Edition SP2 Microsoft Windows Server 2008 Enterprise Edition 0 Microsoft Windows Server 2008 Datacenter Edition SP2 Microsoft Windows Server 2008 Datacenter Edition 0 Microsoft Windows Server 2003 Standard Edition SP2 Microsoft Windows Server 2003 Standard Edition SP1 Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Itanium SP2 Microsoft Windows Server 2003 Itanium SP1 Microsoft Windows Server 2003 Itanium 0 Microsoft Windows Server 2003 Enterprise x64 Edition SP2 Microsoft Windows Server 2003 Enterprise x64 Edition Microsoft Windows Server 2003 Enterprise Edition Itanium Sp2 Itanium Microsoft Windows Server 2003 Enterprise Edition Itanium SP2 Microsoft Windows Server 2003 Enterprise Edition Itanium SP1 Beta 1 Microsoft Windows Server 2003 Enterprise Edition Itanium SP1 Microsoft Windows Server 2003 Enterprise Edition Itanium 0 Microsoft Windows Server 2003 Enterprise Edition SP1 Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Datacenter x64 Edition SP2 Microsoft Windows Server 2003 Datacenter x64 Edition Microsoft Windows Server 2003 Datacenter Edition Itanium SP1 Beta 1 Microsoft Windows Server 2003 Datacenter Edition Itanium SP1 Microsoft Windows Server 2003 Datacenter Edition Itanium 0 Microsoft Windows Server 2003 Datacenter Edition SP1 Beta 1 Microsoft Windows Server 2003 Datacenter Edition SP1 Microsoft Windows Server 2003 Datacenter Edition Microsoft Windows Server 2003 SP2 Microsoft Windows Server 2003 SP1 Microsoft Windows Server 2008 R2 Avaya Meeting Exchange - Webportal 0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 Avaya Conferencing Standard Edition 6.0 SP1 Avaya Conferencing Standard Edition 6.0 Avaya Communication Server 1000 Telephony Manager 4.0 Avaya Communication Server 1000 Telephony Manager 3.0 Avaya Communication Server 1000 Telephony Manager 0 Avaya CallPilot 5.0 Avaya CallPilot 4.0 Avaya CallPilot 0 |
| Not Vulnerable: | |
Discussion
Microsoft Windows WINS Server 'ECommEndDlg()' Local Privilege Escalation Vulnerability
Microsoft Windows WINS server is prone to a local privilege-escalation vulnerability that may be triggered by malicious WINS network packets.
Successful exploits will allow local attackers to execute arbitrary code with local system privileges and potentially compromise the affected computer.
Microsoft Windows WINS server is prone to a local privilege-escalation vulnerability that may be triggered by malicious WINS network packets.
Successful exploits will allow local attackers to execute arbitrary code with local system privileges and potentially compromise the affected computer.
Exploit / POC
Microsoft Windows WINS Server 'ECommEndDlg()' Local Privilege Escalation Vulnerability
The following proof of concept is available:
The following proof of concept is available:
Solution / Fix
Microsoft Windows WINS Server 'ECommEndDlg()' Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references for more information.
Microsoft Windows Server 2008 R2 x64 SP1
Microsoft Windows Server 2008 for 32-bit Systems SP2
Microsoft Windows Server 2003 SP2
Microsoft Windows Server 2008 for x64-based Systems R2
Microsoft Windows Server 2003 Datacenter x64 Edition SP2
Microsoft Windows Server 2003 Standard Edition SP2
Microsoft Windows Server 2008 for x64-based Systems SP2
Microsoft Windows Server 2003 Itanium SP2
Microsoft Windows Server 2003 Enterprise x64 Edition SP2
Solution:
Updates are available. Please see the references for more information.
Microsoft Windows Server 2008 R2 x64 SP1
-
Microsoft Security Update for Windows Server 2008 R2 x64 Edition (KB2571621)
http://www.microsoft.com/downloads/details.aspx?familyid=f58cf343-946c -4e74-bd9c-40ac934a4986
Microsoft Windows Server 2008 for 32-bit Systems SP2
-
Microsoft Security Update for Windows Server 2008 (KB2571621)
http://www.microsoft.com/downloads/details.aspx?familyid=a9039660-3cc2 -470d-a0a5-a70f78074495
Microsoft Windows Server 2003 SP2
-
Microsoft Security Update for Windows Server 2003 (KB2571621)
http://www.microsoft.com/downloads/details.aspx?familyid=1e6ac3b2-752e -49a0-84e5-5a8dfe955299
Microsoft Windows Server 2008 for x64-based Systems R2
-
Microsoft Security Update for Windows Server 2008 R2 x64 Edition (KB2571621)
http://www.microsoft.com/downloads/details.aspx?familyid=f58cf343-946c -4e74-bd9c-40ac934a4986
Microsoft Windows Server 2003 Datacenter x64 Edition SP2
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB2571621)
http://www.microsoft.com/downloads/details.aspx?familyid=f9378339-c58e -4e84-9427-85aeb35b0d99
Microsoft Windows Server 2003 Standard Edition SP2
-
Microsoft Security Update for Windows Server 2003 (KB2571621)
http://www.microsoft.com/downloads/details.aspx?familyid=1e6ac3b2-752e -49a0-84e5-5a8dfe955299
Microsoft Windows Server 2008 for x64-based Systems SP2
-
Microsoft Security Update for Windows Server 2008 x64 Edition (KB2571621)
http://www.microsoft.com/downloads/details.aspx?familyid=5ea78a9b-b1f7 -4e94-b69e-c984e1622ae9
Microsoft Windows Server 2003 Itanium SP2
-
Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB2571621)
http://www.microsoft.com/downloads/details.aspx?familyid=c35c71a8-13b4 -47a6-9763-06f6f65327b1
Microsoft Windows Server 2003 Enterprise x64 Edition SP2
-
Microsoft Security Update for Windows Server 2003 x64 Edition (KB2571621)
http://www.microsoft.com/downloads/details.aspx?familyid=f9378339-c58e -4e84-9427-85aeb35b0d99
References
Microsoft Windows WINS Server 'ECommEndDlg()' Local Privilege Escalation Vulnerability
References:
References:
- Microsoft Windows Homepage (Microsoft)
- Microsoft Security Bulletin MS11-070 (Microsoft)
- MS WINS ECommEndDlg Input Validation Error (CORE Security Technologies)