Microsoft JET/ODBC Patch and RDS Fix Registry Key Vulnerabilities
BID:654
Info
Microsoft JET/ODBC Patch and RDS Fix Registry Key Vulnerabilities
| Bugtraq ID: | 654 |
| Class: | Design Error |
| CVE: | |
| Remote: | No |
| Local: | Yes |
| Published: | Sep 21 1999 12:00AM |
| Updated: | Sep 21 1999 12:00AM |
| Credit: | This vulnerability was identified and posted to Bugtraq on September 22, 1999 by .rain.forest.puppy <[email protected]> |
| Vulnerable: |
Microsoft Windows NT 4.0 SP6a alpha Microsoft Windows NT 4.0 SP6a Microsoft Windows NT 4.0 SP5 alpha Microsoft Windows NT 4.0 SP5 Microsoft Windows NT 4.0 SP4 alpha Microsoft Windows NT 4.0 SP4 Microsoft Windows NT 4.0 SP3 alpha Microsoft Windows NT 4.0 SP3 Microsoft Windows NT 4.0 SP2 alpha Microsoft Windows NT 4.0 SP2 Microsoft Windows NT 4.0 SP1 alpha Microsoft Windows NT 4.0 SP1 Microsoft Windows NT 4.0 alpha Microsoft Windows NT 4.0 Microsoft JET 4.0 SP1 Microsoft Data Access Components (MDAC) 2.1.2.4202.3 (GA) |
| Not Vulnerable: | |
Discussion
Microsoft JET/ODBC Patch and RDS Fix Registry Key Vulnerabilities
Microsoft has made available fixes for the JET/ODBC and RDS vulnerabilities. These fixes implement specific Registry Key values to restrict "malicious activity". The Registry Keys include:
for JET/ODBC:
HKEY_LOCAL_MACHINE\Software\Microsoft\Jet\3.5\Engines\SandboxMode
for RDS:
HKEY_LOCAL_MACHINE\Software\Microsoft\DataFactory\HandlerInfo
Value: handlerRequired
DWORD=1
The Security Permissions over these Registry Keys are Set to "Everyone:Special Access". Special Access, in these instances, includes 'Set Value'. This permission allows members of the Everyone Group (Domain Users, Users, Guests, etc.) to modify the value of these keys, including the ability to disable the security features which may have been enabled by the administrator. Disabling the Data Factory\HandlerInfo setting ("handlerRequired DWORD=0") may open the host to exploit via the MDAC RDS exploit as described in Bugtraq ID 529 <http://www.securityfocus.com/bid/529.html>.
Microsoft has made available fixes for the JET/ODBC and RDS vulnerabilities. These fixes implement specific Registry Key values to restrict "malicious activity". The Registry Keys include:
for JET/ODBC:
HKEY_LOCAL_MACHINE\Software\Microsoft\Jet\3.5\Engines\SandboxMode
for RDS:
HKEY_LOCAL_MACHINE\Software\Microsoft\DataFactory\HandlerInfo
Value: handlerRequired
DWORD=1
The Security Permissions over these Registry Keys are Set to "Everyone:Special Access". Special Access, in these instances, includes 'Set Value'. This permission allows members of the Everyone Group (Domain Users, Users, Guests, etc.) to modify the value of these keys, including the ability to disable the security features which may have been enabled by the administrator. Disabling the Data Factory\HandlerInfo setting ("handlerRequired DWORD=0") may open the host to exploit via the MDAC RDS exploit as described in Bugtraq ID 529 <http://www.securityfocus.com/bid/529.html>.
Exploit / POC
Microsoft JET/ODBC Patch and RDS Fix Registry Key Vulnerabilities
Modify the HKEY_Local_Machine\Software\Microsoft\DataFactory\HandlerInfo Registry Key value "handlerRequired" to DWORD=0
Modify the HKEY_Local_Machine\Software\Microsoft\DataFactory\HandlerInfo Registry Key value "handlerRequired" to DWORD=0
Solution / Fix
Microsoft JET/ODBC Patch and RDS Fix Registry Key Vulnerabilities
Solution:
Microsoft has released a hotfix for this issue, available at:
Intel: http://www.microsoft.com/downloads/release.asp?ReleaseID=19172
Alpha: http://www.microsoft.com/downloads/release.asp?ReleaseID=19173
Microsoft Windows NT 4.0 SP5 alpha
Microsoft Windows NT 4.0 SP1
Microsoft Windows NT 4.0 SP4 alpha
Microsoft Windows NT 4.0
Microsoft Windows NT 4.0 alpha
Microsoft Windows NT 4.0 SP1 alpha
Microsoft Windows NT 4.0 SP2
Microsoft Windows NT 4.0 SP2 alpha
Microsoft Windows NT 4.0 SP6a
Microsoft Windows NT 4.0 SP3
Microsoft Windows NT 4.0 SP6a alpha
Microsoft Windows NT 4.0 SP5
Microsoft Windows NT 4.0 SP4
Microsoft Windows NT 4.0 SP3 alpha
Solution:
Microsoft has released a hotfix for this issue, available at:
Intel: http://www.microsoft.com/downloads/release.asp?ReleaseID=19172
Alpha: http://www.microsoft.com/downloads/release.asp?ReleaseID=19173
Microsoft Windows NT 4.0 SP5 alpha
-
Microsoft Q250625
http://download.microsoft.com/download/winntsp/Patch/regacl/ALPHA/EN-U S/Q250625A.EXE
Microsoft Windows NT 4.0 SP1
-
Microsoft Q250625
http://download.microsoft.com/download/winntsp/Patch/regacl/NT4/EN-US/ Q250625i.EXE
Microsoft Windows NT 4.0 SP4 alpha
-
Microsoft Q250625
http://download.microsoft.com/download/winntsp/Patch/regacl/ALPHA/EN-U S/Q250625A.EXE
Microsoft Windows NT 4.0
-
Microsoft Q250625
http://download.microsoft.com/download/winntsp/Patch/regacl/NT4/EN-US/ Q250625i.EXE
Microsoft Windows NT 4.0 alpha
-
Microsoft Q250625
http://download.microsoft.com/download/winntsp/Patch/regacl/ALPHA/EN-U S/Q250625A.EXE
Microsoft Windows NT 4.0 SP1 alpha
-
Microsoft Q250625
http://download.microsoft.com/download/winntsp/Patch/regacl/ALPHA/EN-U S/Q250625A.EXE
Microsoft Windows NT 4.0 SP2
-
Microsoft Q250625
http://download.microsoft.com/download/winntsp/Patch/regacl/NT4/EN-US/ Q250625i.EXE
Microsoft Windows NT 4.0 SP2 alpha
-
Microsoft Q250625
http://download.microsoft.com/download/winntsp/Patch/regacl/ALPHA/EN-U S/Q250625A.EXE
Microsoft Windows NT 4.0 SP6a
-
Microsoft Q250625
http://download.microsoft.com/download/winntsp/Patch/regacl/NT4/EN-US/ Q250625i.EXE
Microsoft Windows NT 4.0 SP3
-
Microsoft Q250625
http://download.microsoft.com/download/winntsp/Patch/regacl/NT4/EN-US/ Q250625i.EXE
Microsoft Windows NT 4.0 SP6a alpha
-
Microsoft Q250625
http://download.microsoft.com/download/winntsp/Patch/regacl/ALPHA/EN-U S/Q250625A.EXE
Microsoft Windows NT 4.0 SP5
-
Microsoft Q250625
http://download.microsoft.com/download/winntsp/Patch/regacl/NT4/EN-US/ Q250625i.EXE
Microsoft Windows NT 4.0 SP4
-
Microsoft Q250625
http://download.microsoft.com/download/winntsp/Patch/regacl/NT4/EN-US/ Q250625i.EXE
Microsoft Windows NT 4.0 SP3 alpha
References
Microsoft JET/ODBC Patch and RDS Fix Registry Key Vulnerabilities
References:
References: