Microsoft Windows XP Redirector Privilege Escalation Vulnerability
BID:6778
Info
Microsoft Windows XP Redirector Privilege Escalation Vulnerability
| Bugtraq ID: | 6778 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0004 |
| Remote: | No |
| Local: | Yes |
| Published: | Feb 05 2003 12:00AM |
| Updated: | Jul 11 2009 08:06PM |
| Credit: | Discovery is credited to NSFocus. |
| Vulnerable: |
Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows XP 64-bit Edition SP1 Microsoft Windows XP 64-bit Edition |
| Not Vulnerable: |
Microsoft Windows NT Workstation 4.0 SP6a Microsoft Windows NT Workstation 4.0 SP6 Microsoft Windows NT Workstation 4.0 SP5 Microsoft Windows NT Workstation 4.0 SP4 Microsoft Windows NT Workstation 4.0 SP3 Microsoft Windows NT Workstation 4.0 SP2 Microsoft Windows NT Workstation 4.0 SP1 Microsoft Windows NT Workstation 4.0 Microsoft Windows NT Terminal Server 4.0 SP6a Microsoft Windows NT Terminal Server 4.0 SP6 Microsoft Windows NT Terminal Server 4.0 SP5 Microsoft Windows NT Terminal Server 4.0 SP4 Microsoft Windows NT Terminal Server 4.0 SP3 Microsoft Windows NT Terminal Server 4.0 SP2 Microsoft Windows NT Terminal Server 4.0 SP1 Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6 Microsoft Windows NT Enterprise Server 4.0 SP5 Microsoft Windows NT Enterprise Server 4.0 SP4 Microsoft Windows NT Enterprise Server 4.0 SP3 Microsoft Windows NT Enterprise Server 4.0 SP2 Microsoft Windows NT Enterprise Server 4.0 SP1 Microsoft Windows NT Enterprise Server 4.0 Microsoft Windows 2000 Terminal Services SP3 Microsoft Windows 2000 Terminal Services SP2 Microsoft Windows 2000 Terminal Services SP1 Microsoft Windows 2000 Terminal Services Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
Discussion
Microsoft Windows XP Redirector Privilege Escalation Vulnerability
The Microsoft Windows XP Redirector does not properly handle certain parameters that are passed to it. If one of these parameters was unusually long, a buffer could be overrun, resulting in either Windows XP crashing or code execution with elevated privileges.
The Microsoft Windows XP Redirector does not properly handle certain parameters that are passed to it. If one of these parameters was unusually long, a buffer could be overrun, resulting in either Windows XP crashing or code execution with elevated privileges.
Exploit / POC
Microsoft Windows XP Redirector Privilege Escalation Vulnerability
The following proof of concept was provided:
c:\> net use \\AAAA...AAA\A
The following proof of concept was provided:
c:\> net use \\AAAA...AAA\A
Solution / Fix
Microsoft Windows XP Redirector Privilege Escalation Vulnerability
Solution:
Microsoft has released fixes:
Microsoft Windows XP Home
Microsoft Windows XP Professional
Microsoft Windows XP Professional SP1
Microsoft Windows XP 64-bit Edition
Microsoft Windows XP 64-bit Edition SP1
Microsoft Windows XP Home SP1
Solution:
Microsoft has released fixes:
Microsoft Windows XP Home
-
Microsoft Q810577
http://microsoft.com/downloads/details.aspx?FamilyId=33DABD1F-505E-48E D-B9BD-CDAC0F8A2BC1&displaylang=en
Microsoft Windows XP Professional
-
Microsoft Q810577
http://microsoft.com/downloads/details.aspx?FamilyId=33DABD1F-505E-48E D-B9BD-CDAC0F8A2BC1&displaylang=en
Microsoft Windows XP Professional SP1
-
Microsoft Q810577
http://microsoft.com/downloads/details.aspx?FamilyId=33DABD1F-505E-48E D-B9BD-CDAC0F8A2BC1&displaylang=en
Microsoft Windows XP 64-bit Edition
-
Microsoft Q810577
http://microsoft.com/downloads/details.aspx?FamilyId=A2258F4E-9A69-453 7-9469-0DDEB4BB76F8&displaylang=en
Microsoft Windows XP 64-bit Edition SP1
-
Microsoft Q810577
http://microsoft.com/downloads/details.aspx?FamilyId=A2258F4E-9A69-453 7-9469-0DDEB4BB76F8&displaylang=en
Microsoft Windows XP Home SP1
References
Microsoft Windows XP Redirector Privilege Escalation Vulnerability
References:
References:
- Microsoft Security Bulletin MS03-005 (Microsoft)
- NSFOCUS SA2003-01: Microsoft Windows XP Redirector Local Buffer Overflow Vulnera (NSFCOSU Security Team
)