Microsoft PPTP Server Buffer Overflow Vulnerability
BID:5807
Info
Microsoft PPTP Server Buffer Overflow Vulnerability
| Bugtraq ID: | 5807 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2002-1214 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 26 2002 12:00AM |
| Updated: | Jul 11 2009 05:06PM |
| Credit: | Discovery of this vulnerability credited to Stephan Hoffmann and Thomas Unterleitner on behalf of phion Information Technologies. |
| Vulnerable: |
Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows XP 64-bit Edition SP1 Microsoft Windows XP 64-bit Edition Microsoft Windows 2000 Terminal Services SP3 Microsoft Windows 2000 Terminal Services SP2 Microsoft Windows 2000 Terminal Services SP1 Microsoft Windows 2000 Terminal Services Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Discussion
Microsoft PPTP Server Buffer Overflow Vulnerability
A buffer overflow vulnerability has been reported for Microsoft's PPTP (Point to Point Tunneling Protocol) implementation. The vulnerability reportedly exists in both the PPTP server and client applications. It is possible for a malicious attacker to craft a packet which causes memory to be corrupted with attacker-supplied data and send it to the PPTP process. This may result in the execution of attacker-supplied malicious code.
A buffer overflow vulnerability has been reported for Microsoft's PPTP (Point to Point Tunneling Protocol) implementation. The vulnerability reportedly exists in both the PPTP server and client applications. It is possible for a malicious attacker to craft a packet which causes memory to be corrupted with attacker-supplied data and send it to the PPTP process. This may result in the execution of attacker-supplied malicious code.
Exploit / POC
Microsoft PPTP Server Buffer Overflow Vulnerability
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Solution / Fix
Microsoft PPTP Server Buffer Overflow Vulnerability
Solution:
Microsoft has released fixes:
Microsoft Windows 2000 Professional
Microsoft Windows 2000 Server SP2
Microsoft Windows 2000 Advanced Server SP3
Microsoft Windows XP Home
Microsoft Windows 2000 Advanced Server SP1
Microsoft Windows XP Home SP1
Microsoft Windows 2000 Advanced Server SP2
Microsoft Windows 2000 Terminal Services SP3
Microsoft Windows XP 64-bit Edition SP1
Microsoft Windows 2000 Professional SP1
Microsoft Windows 2000 Server SP3
Microsoft Windows XP 64-bit Edition
Microsoft Windows 2000 Terminal Services SP2
Microsoft Windows 2000 Server SP1
Microsoft Windows 2000 Professional SP3
Microsoft Windows XP Professional
Microsoft Windows 2000 Professional SP2
Microsoft Windows 2000 Terminal Services SP1
Microsoft Windows XP Professional SP1
Microsoft Windows 2000 Advanced Server
Microsoft Windows 2000 Terminal Services
Microsoft Windows 2000 Server
Solution:
Microsoft has released fixes:
Microsoft Windows 2000 Professional
-
Microsoft Q329834
http://www.microsoft.com/windows2000/downloads/critical/q329834/defaul t.asp?FinishURL=%2Fdownloads%2Frelease%2Easp%3FReleaseID%3D43606%26red irect%3Dno
Microsoft Windows 2000 Server SP2
-
Microsoft Q329834
http://www.microsoft.com/windows2000/downloads/critical/q329834/defaul t.asp?FinishURL=%2Fdownloads%2Frelease%2Easp%3FReleaseID%3D43606%26red irect%3Dno
Microsoft Windows 2000 Advanced Server SP3
-
Microsoft Q329834
http://www.microsoft.com/windows2000/downloads/critical/q329834/defaul t.asp?FinishURL=%2Fdownloads%2Frelease%2Easp%3FReleaseID%3D43606%26red irect%3Dno
Microsoft Windows XP Home
-
Microsoft Q329834
http://download.microsoft.com/download/whistler/Patch/Q329834/WXP/EN-U S/Q329834_WXP_SP2_x86_ENU.exe
Microsoft Windows 2000 Advanced Server SP1
-
Microsoft Q329834
http://www.microsoft.com/windows2000/downloads/critical/q329834/defaul t.asp?FinishURL=%2Fdownloads%2Frelease%2Easp%3FReleaseID%3D43606%26red irect%3Dno
Microsoft Windows XP Home SP1
-
Microsoft Q329834
http://download.microsoft.com/download/whistler/Patch/Q329834/WXP/EN-U S/Q329834_WXP_SP2_x86_ENU.exe
Microsoft Windows 2000 Advanced Server SP2
-
Microsoft Q329834
http://www.microsoft.com/windows2000/downloads/critical/q329834/defaul t.asp?FinishURL=%2Fdownloads%2Frelease%2Easp%3FReleaseID%3D43606%26red irect%3Dno
Microsoft Windows 2000 Terminal Services SP3
-
Microsoft Q329834
http://www.microsoft.com/windows2000/downloads/critical/q329834/defaul t.asp?FinishURL=%2Fdownloads%2Frelease%2Easp%3FReleaseID%3D43606%26red irect%3Dno
Microsoft Windows XP 64-bit Edition SP1
-
Microsoft Q329834
http://download.microsoft.com/download/whistler/Patch/Q329834/W64XP/EN -US/Q329834_WXP_SP2_ia64_ENU.exe
Microsoft Windows 2000 Professional SP1
-
Microsoft Q329834
http://www.microsoft.com/windows2000/downloads/critical/q329834/defaul t.asp?FinishURL=%2Fdownloads%2Frelease%2Easp%3FReleaseID%3D43606%26red irect%3Dno
Microsoft Windows 2000 Server SP3
-
Microsoft Q329834
http://www.microsoft.com/windows2000/downloads/critical/q329834/defaul t.asp?FinishURL=%2Fdownloads%2Frelease%2Easp%3FReleaseID%3D43606%26red irect%3Dno
Microsoft Windows XP 64-bit Edition
-
Microsoft Q329834
http://download.microsoft.com/download/whistler/Patch/Q329834/W64XP/EN -US/Q329834_WXP_SP2_ia64_ENU.exe
Microsoft Windows 2000 Terminal Services SP2
-
Microsoft Q329834
http://www.microsoft.com/windows2000/downloads/critical/q329834/defaul t.asp?FinishURL=%2Fdownloads%2Frelease%2Easp%3FReleaseID%3D43606%26red irect%3Dno
Microsoft Windows 2000 Server SP1
-
Microsoft Q329834
http://www.microsoft.com/windows2000/downloads/critical/q329834/defaul t.asp?FinishURL=%2Fdownloads%2Frelease%2Easp%3FReleaseID%3D43606%26red irect%3Dno
Microsoft Windows 2000 Professional SP3
-
Microsoft Q329834
http://www.microsoft.com/windows2000/downloads/critical/q329834/defaul t.asp?FinishURL=%2Fdownloads%2Frelease%2Easp%3FReleaseID%3D43606%26red irect%3Dno
Microsoft Windows XP Professional
-
Microsoft Q329834
http://download.microsoft.com/download/whistler/Patch/Q329834/WXP/EN-U S/Q329834_WXP_SP2_x86_ENU.exe
Microsoft Windows 2000 Professional SP2
-
Microsoft Q329834
http://www.microsoft.com/windows2000/downloads/critical/q329834/defaul t.asp?FinishURL=%2Fdownloads%2Frelease%2Easp%3FReleaseID%3D43606%26red irect%3Dno
Microsoft Windows 2000 Terminal Services SP1
-
Microsoft Q329834
http://www.microsoft.com/windows2000/downloads/critical/q329834/defaul t.asp?FinishURL=%2Fdownloads%2Frelease%2Easp%3FReleaseID%3D43606%26red irect%3Dno
Microsoft Windows XP Professional SP1
-
Microsoft Q329834
http://download.microsoft.com/download/whistler/Patch/Q329834/WXP/EN-U S/Q329834_WXP_SP2_x86_ENU.exe
Microsoft Windows 2000 Advanced Server
-
Microsoft Q329834
http://www.microsoft.com/windows2000/downloads/critical/q329834/defaul t.asp?FinishURL=%2Fdownloads%2Frelease%2Easp%3FReleaseID%3D43606%26red irect%3Dno
Microsoft Windows 2000 Terminal Services
-
Microsoft Q329834
http://www.microsoft.com/windows2000/downloads/critical/q329834/defaul t.asp?FinishURL=%2Fdownloads%2Frelease%2Easp%3FReleaseID%3D43606%26red irect%3Dno
Microsoft Windows 2000 Server
References
Microsoft PPTP Server Buffer Overflow Vulnerability
References:
References:
- Microsoft PPTP DoS (CORE Security)
- Microsoft Security Bulletin MS02-063 (Microsoft)