Microsoft Windows DNS Resource Record Cache Corruption Vulnerability
BID:6791
Info
Microsoft Windows DNS Resource Record Cache Corruption Vulnerability
| Bugtraq ID: | 6791 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 31 2001 12:00AM |
| Updated: | Aug 31 2001 12:00AM |
| Credit: | This vulnerability was announced by CERT. |
| Vulnerable: |
Microsoft Windows NT Terminal Server 4.0 SP6 Microsoft Windows NT Terminal Server 4.0 SP5 Microsoft Windows NT Terminal Server 4.0 SP4 Microsoft Windows NT Terminal Server 4.0 SP3 Microsoft Windows NT Terminal Server 4.0 SP2 Microsoft Windows NT Terminal Server 4.0 SP1 Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6 Microsoft Windows NT Enterprise Server 4.0 SP5 Microsoft Windows NT Enterprise Server 4.0 SP4 Microsoft Windows NT Enterprise Server 4.0 SP3 Microsoft Windows NT Enterprise Server 4.0 SP2 Microsoft Windows NT Enterprise Server 4.0 SP1 Microsoft Windows NT Enterprise Server 4.0 Microsoft Windows 2000 Server Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Discussion
Microsoft Windows DNS Resource Record Cache Corruption Vulnerability
A vulnerability has been discovered in the DNS server on the Windows NT and Windows 2000 operating systems. The problem occurs in the caching of glue records. It has been reported that glue records received from non-delegated name servers will be cached by default. This may allow for a malicious server to respond to a legitimate DNS query with a spoofed DNS response, designed to contain the necessary glue record characteristics.
A client making a request for a legitimate host may receive a corrupted record located in the DNS server's cache. This could result in the user being directed to an unexpected and malicious website.
A vulnerability has been discovered in the DNS server on the Windows NT and Windows 2000 operating systems. The problem occurs in the caching of glue records. It has been reported that glue records received from non-delegated name servers will be cached by default. This may allow for a malicious server to respond to a legitimate DNS query with a spoofed DNS response, designed to contain the necessary glue record characteristics.
A client making a request for a legitimate host may receive a corrupted record located in the DNS server's cache. This could result in the user being directed to an unexpected and malicious website.
Exploit / POC
Microsoft Windows DNS Resource Record Cache Corruption Vulnerability
New information made available to Symantec suggests that this issue is currently being exploited in the wild.
New information made available to Symantec suggests that this issue is currently being exploited in the wild.
Solution / Fix
Microsoft Windows DNS Resource Record Cache Corruption Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Windows DNS Resource Record Cache Corruption Vulnerability
References:
References:
- How to Prevent DNS Cache Pollution (Microsoft)
- Vulnerability Note VU#109475 (CERT)