Microsoft Commerce Server ISAPI Buffer Overflow Variation Vulnerability
BID:5112
Info
Microsoft Commerce Server ISAPI Buffer Overflow Variation Vulnerability
| Bugtraq ID: | 5112 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-0623 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 26 2002 12:00AM |
| Updated: | Jan 25 2014 06:03AM |
| Credit: | Discovery is credited to Microsoft. |
| Vulnerable: |
Microsoft Commerce Server 2002 Microsoft Commerce Server 2000 SP2 Microsoft Commerce Server 2000 SP1 Microsoft Commerce Server 2000 |
| Not Vulnerable: | |
Discussion
Microsoft Commerce Server ISAPI Buffer Overflow Variation Vulnerability
AuthFilter is an ISAPI filter used by Commerce Server to support various methods of user authentication. It is important to note that this ISAPI filter is only contained in Commerce Server and not in Internet Information Server.
AuthFilter has been found to contain an unchecked buffer which could be exploited to cause a failure of the Commerce Server or execution of arbitrary code. AuthFilter is installed by default, but must be explicitly activated for this issue to be exploited.
The Commerce Server process runs with LocalSystem privileges.
This is a variation of the vulnerability discussed in Bugtraq ID 4157 / Microsoft Security Bulletin MS02-010. Reportedly, this issue varies in the specific manner in which it may be exploited.
AuthFilter is an ISAPI filter used by Commerce Server to support various methods of user authentication. It is important to note that this ISAPI filter is only contained in Commerce Server and not in Internet Information Server.
AuthFilter has been found to contain an unchecked buffer which could be exploited to cause a failure of the Commerce Server or execution of arbitrary code. AuthFilter is installed by default, but must be explicitly activated for this issue to be exploited.
The Commerce Server process runs with LocalSystem privileges.
This is a variation of the vulnerability discussed in Bugtraq ID 4157 / Microsoft Security Bulletin MS02-010. Reportedly, this issue varies in the specific manner in which it may be exploited.
Exploit / POC
Microsoft Commerce Server ISAPI Buffer Overflow Variation Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Commerce Server ISAPI Buffer Overflow Variation Vulnerability
Solution:
Microsoft has provided a patch to address this issue:
Microsoft Commerce Server 2000 SP2
Microsoft Commerce Server 2000
Microsoft Commerce Server 2002
Solution:
Microsoft has provided a patch to address this issue:
Microsoft Commerce Server 2000 SP2
-
Microsoft Q322273
http://download.microsoft.com/download/comserver/Patch/1.1/NT5/EN-US/Q 322273_EN.EXE
Microsoft Commerce Server 2000
-
Microsoft Q322273
http://download.microsoft.com/download/comserver/Patch/1.1/NT5/EN-US/Q 322273_EN.EXE
Microsoft Commerce Server 2002
References
Microsoft Commerce Server ISAPI Buffer Overflow Variation Vulnerability
References:
References:
- Microsoft Security Bulletin MS02-033 (Microsoft)