Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability
BID:8205
Info
Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability
| Bugtraq ID: | 8205 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0352 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 16 2003 12:00AM |
| Updated: | Jul 11 2009 10:56PM |
| Credit: | Discovery of this vulnerability has been credited to The Last Stage of Delirium Research Group. |
| Vulnerable: |
Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows XP 64-bit Edition SP1 Microsoft Windows XP 64-bit Edition Microsoft Windows Server 2003 Web Edition Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Enterprise Edition Itanium 0 Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Datacenter Edition Itanium 0 Microsoft Windows Server 2003 Datacenter Edition Microsoft Windows NT Workstation 4.0 SP6a Microsoft Windows NT Workstation 4.0 SP6 Microsoft Windows NT Workstation 4.0 SP5 Microsoft Windows NT Workstation 4.0 SP4 Microsoft Windows NT Workstation 4.0 SP3 Microsoft Windows NT Workstation 4.0 SP2 Microsoft Windows NT Workstation 4.0 SP1 Microsoft Windows NT Workstation 4.0 Microsoft Windows NT Terminal Server 4.0 SP6 Microsoft Windows NT Terminal Server 4.0 SP5 Microsoft Windows NT Terminal Server 4.0 SP4 Microsoft Windows NT Terminal Server 4.0 SP3 Microsoft Windows NT Terminal Server 4.0 SP2 Microsoft Windows NT Terminal Server 4.0 SP1 Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6 Microsoft Windows NT Enterprise Server 4.0 SP5 Microsoft Windows NT Enterprise Server 4.0 SP4 Microsoft Windows NT Enterprise Server 4.0 SP3 Microsoft Windows NT Enterprise Server 4.0 SP2 Microsoft Windows NT Enterprise Server 4.0 SP1 Microsoft Windows NT Enterprise Server 4.0 Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server Compaq OpenVMS 7.3 -1 Alpha Compaq OpenVMS 7.3 VAX Compaq OpenVMS 7.3 Alpha Compaq OpenVMS 7.2.1 Alpha Compaq OpenVMS 7.2 -2 Alpha Compaq OpenVMS 7.2 -1H2 Alpha Compaq OpenVMS 7.2 -1H1 Alpha Compaq OpenVMS 7.2 VAX Compaq OpenVMS 7.2 Alpha Compaq OpenVMS 7.1 -2 Alpha Compaq OpenVMS 7.1 VAX Compaq OpenVMS 7.1 Alpha Compaq OpenVMS 6.2 -1H3 Alpha Compaq OpenVMS 6.2 -1H2 Alpha Compaq OpenVMS 6.2 -1H1 Alpha Compaq OpenVMS 6.2 VAX Compaq OpenVMS 6.2 Alpha Cisco Wireless Lan Solution Engine Cisco VPN/Security Management Solution Cisco Voice Manager Cisco User Registration Tool Cisco uOne Enterprise Edition Cisco uOne 4.0 Cisco uOne 3.0 Cisco uOne 2.0 Cisco uOne 1.0 Cisco Unity Server 4.0 Cisco Unity Server 3.3 Cisco Unity Server 3.2 Cisco Unity Server 3.1 Cisco Unity Server 3.0 Cisco Unity Server 2.46 Cisco Unity Server 2.4 Cisco Unity Server 2.3 Cisco Unity Server 2.2 Cisco Unity Server 2.1 Cisco Unity Server 2.0 Cisco Unity Server Cisco Transport Manager Cisco Trailhead Cisco SN 5420 Storage Router 1.1.3 Cisco SN 5420 Storage Router 1.1 (7) Cisco SN 5420 Storage Router 1.1 (5) Cisco SN 5420 Storage Router 1.1 (4) Cisco SN 5420 Storage Router 1.1 (3) Cisco SN 5420 Storage Router 1.1 (2) Cisco Small Network Management Solution Cisco Service Management Cisco Secure Scanner Cisco Secure Policy Manager 3.0.1 Cisco Secure ACS for Windows Server 3.2 Cisco Secure ACS for Windows NT 3.1.1 Cisco Secure ACS for Windows NT 3.0.3 Cisco Secure ACS for Windows NT 3.0 .1 Cisco Secure ACS for Windows NT 3.0 Cisco Secure ACS for Windows NT 2.6.4 Cisco Secure ACS for Windows NT 2.6.3 Cisco Secure ACS for Windows NT 2.6.2 Cisco Secure ACS for Windows NT 2.6 Cisco Secure ACS for Windows NT 2.5 Cisco Secure ACS for Windows NT 2.4 Cisco Secure ACS for Windows NT 2.3 Cisco Secure ACS for Windows NT 2.1 Cisco Secure Access Control Server 3.2.1 Cisco Routed Wan Management Cisco QoS Policy Manager Cisco Personal Assistant Cisco Networking Services for Active Directory Cisco Network Registar Cisco Media Blender Cisco Lan Management Solution Cisco IP/VC 3540 Video Rate Matching Module Cisco IP/VC 3540 Application Server Cisco IP Telephony Environment Monitor Cisco IP Contact Center Express Cisco Internet Service Node Cisco Intelligent Contact Manager Cisco Emergency Responder Cisco E-Mail Manager Cisco Dynamic Content Adapter Cisco DOCSIS CPE Configurator Cisco Customer Response Application Server Cisco Conference Connection Cisco Collaboration Server Cisco CiscoWorks VPN/Security Management Solution Cisco Call Manager 3.3 (3) Cisco Call Manager 3.3 Cisco Call Manager 3.2 Cisco Call Manager 3.1 (3a) Cisco Call Manager 3.1 (2) Cisco Call Manager 3.1 Cisco Call Manager 3.0 Cisco Call Manager 2.0 Cisco Call Manager 1.0 Cisco Call Manager Cisco Building BroadBand Service Manager Hotspot 1.0 Cisco Building Broadband Service Manager (BBSM) 5.2 Cisco Building Broadband Service Manager (BBSM) 5.1 Cisco Broadband Troubleshooter |
| Not Vulnerable: |
Cisco Secure Access Control Server 3.2.2 Cisco Secure Access Control Server 3.2 (1.20) |
Discussion
Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability
A buffer overrun vulnerability has been reported in Microsoft Windows that can be exploited remotely via a DCOM RPC interface that listens on TCP/UDP port 135. The issue is due to insufficient bounds checking of client DCOM object activation requests. Exploitation of this issue could result in execution of malicious instructions with Local System privileges on an affected system.
This issue may be exposed on other ports that the RPC Endpoint Mapper listens on, such as TCP ports 139, 135, 445 and 593. This has not been confirmed. Under some configurations the Endpoint Mapper may receive traffic via port 80.
** There have been unconfirmed reports that Windows 9x systems with certain software installed may also be vulnerable to this issue. Reportedly, Windows 98 systems with .NET software installed may be vulnerable according to scans using various DCOM RPC vulnerability scanning tools. Symantec has not confirmed this behaviour and it may in fact be due to false positives generated by the scanners.
A buffer overrun vulnerability has been reported in Microsoft Windows that can be exploited remotely via a DCOM RPC interface that listens on TCP/UDP port 135. The issue is due to insufficient bounds checking of client DCOM object activation requests. Exploitation of this issue could result in execution of malicious instructions with Local System privileges on an affected system.
This issue may be exposed on other ports that the RPC Endpoint Mapper listens on, such as TCP ports 139, 135, 445 and 593. This has not been confirmed. Under some configurations the Endpoint Mapper may receive traffic via port 80.
** There have been unconfirmed reports that Windows 9x systems with certain software installed may also be vulnerable to this issue. Reportedly, Windows 98 systems with .NET software installed may be vulnerable according to scans using various DCOM RPC vulnerability scanning tools. Symantec has not confirmed this behaviour and it may in fact be due to false positives generated by the scanners.
Exploit / POC
Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
August 02, 2003:
There is currently at least one autorooter-enabled IRC bot circulating
which exploits this vulnerability. At this time, the IRC bot does not
appear to be automated into a worm.
August 11, 2003:
An additional exploit (kaht2.zip) has been released.
November 7, 2003:
A new exploit designed to bypass various Windows memory protection schemes is available. The exploit works by using a 'ret-into-libc' chaining procedure, which copies a payload into a newly allocated page modified using undocumented API functions to be executable. This exploit, rpc!exec.c is available below.
An exploit has been released as part of the MetaSploit Framework 2.0.
The following exploits are available:
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
August 02, 2003:
There is currently at least one autorooter-enabled IRC bot circulating
which exploits this vulnerability. At this time, the IRC bot does not
appear to be automated into a worm.
August 11, 2003:
An additional exploit (kaht2.zip) has been released.
November 7, 2003:
A new exploit designed to bypass various Windows memory protection schemes is available. The exploit works by using a 'ret-into-libc' chaining procedure, which copies a payload into a newly allocated page modified using undocumented API functions to be executable. This exploit, rpc!exec.c is available below.
An exploit has been released as part of the MetaSploit Framework 2.0.
The following exploits are available:
- /data/vulnerabilities/exploits/kaht2.zip
- /data/vulnerabilities/exploits/rpc!exec.c
- /data/vulnerabilities/exploits/msrpc_dcom_ms03_026.pm
- /data/vulnerabilities/exploits/dcomrpc.c
- /data/vulnerabilities/exploits/dcom.c
- /data/vulnerabilities/exploits/DComExpl_UnixWin32.zip
- /data/vulnerabilities/exploits/oc192_rpc_dcom.c
- /data/vulnerabilities/exploits/07.30.dcom48.c
- /data/vulnerabilities/exploits/30.07.03.dcom.c
- /data/vulnerabilities/exploits/0x82-dcomrpc_usemgret.c
- /data/vulnerabilities/exploits/oc192-dcom.c
Solution / Fix
Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability
Solution:
eEye has released a free scanning tool for administrators to detect systems vulnerable to this issue. Please check the references section for a link to download this utility.
** Several reports state that the RPC/DCOM service may still be vulnerable to a denial of service attack even if the Microsoft-supplied patch has been applied.
Microsoft has released patches to address this issue. Note that Windows
NT 4.0 Workstation reached its end of life on June 30th, 2003. Because of
this, Microsoft has not released a supported NT 4.0 Workstation patch.
The Windows NT 4.0 Server patch may work on NT 4.0 Workstation, however,
this has not been tested nor is it supported by Microsoft.
** CERT/CC reported an unrelated vulnerability in DCE implementations provided by various vendors that may be triggered by exploits or scanning tools associated with this issue. Please see BID 8371 for further details on the availability of fixes for affected implementations. It should be noted that this is a side-effect that may cause problems with DCE implementations, but does not affect Microsoft Windows itself.
Microsoft has released an update to their advisory stated that while the provided Windows 2000 patch will install on Windows 2000 SP2, it is unsupported. Microsoft recommends users to upgrade to a supported Service Pack. Further information can be found in MS03-026.
Cisco has released an advisory detailing products affected by this vulnerability, as well as making fix information available. Additional details available in referenced advisory.
Microsoft has released new fixes that supersede the original fixes for this issue. Administrators are advised to apply the new patches as they also address BID 8458, 8459, and 8460 in addition to this BID.
HP has made fixes available for OpenVMS.
Microsoft Windows NT Terminal Server 4.0 SP6
Microsoft Windows Server 2003 Standard Edition
Microsoft Windows XP Professional
Cisco Conference Connection
Microsoft Windows NT Workstation 4.0 SP6a
Microsoft Windows 2000 Advanced Server SP4
Microsoft Windows 2000 Professional SP3
Microsoft Windows 2000 Professional SP2
Microsoft Windows 2000 Advanced Server SP3
Microsoft Windows XP Home SP1
Microsoft Windows XP 64-bit Edition
Cisco IP Contact Center Express
Microsoft Windows 2000 Professional SP4
Microsoft Windows 2000 Server SP2
Microsoft Windows 2000 Advanced Server SP2
Cisco Call Manager 1.0
Cisco Call Manager 3.0
Cisco Call Manager 3.1 (3a)
Cisco Call Manager 3.1 (2)
Cisco Call Manager 3.3 (3)
Compaq OpenVMS 6.2 VAX
Compaq OpenVMS 6.2 -1H2 Alpha
Compaq OpenVMS 7.1 VAX
Compaq OpenVMS 7.1 Alpha
Compaq OpenVMS 7.2 Alpha
Compaq OpenVMS 7.2 VAX
Compaq OpenVMS 7.2 -1H1 Alpha
Compaq OpenVMS 7.2 -1H2 Alpha
Compaq OpenVMS 7.2 -2 Alpha
Compaq OpenVMS 7.3 Alpha
Compaq OpenVMS 7.3 -1 Alpha
Solution:
eEye has released a free scanning tool for administrators to detect systems vulnerable to this issue. Please check the references section for a link to download this utility.
** Several reports state that the RPC/DCOM service may still be vulnerable to a denial of service attack even if the Microsoft-supplied patch has been applied.
Microsoft has released patches to address this issue. Note that Windows
NT 4.0 Workstation reached its end of life on June 30th, 2003. Because of
this, Microsoft has not released a supported NT 4.0 Workstation patch.
The Windows NT 4.0 Server patch may work on NT 4.0 Workstation, however,
this has not been tested nor is it supported by Microsoft.
** CERT/CC reported an unrelated vulnerability in DCE implementations provided by various vendors that may be triggered by exploits or scanning tools associated with this issue. Please see BID 8371 for further details on the availability of fixes for affected implementations. It should be noted that this is a side-effect that may cause problems with DCE implementations, but does not affect Microsoft Windows itself.
Microsoft has released an update to their advisory stated that while the provided Windows 2000 patch will install on Windows 2000 SP2, it is unsupported. Microsoft recommends users to upgrade to a supported Service Pack. Further information can be found in MS03-026.
Cisco has released an advisory detailing products affected by this vulnerability, as well as making fix information available. Additional details available in referenced advisory.
Microsoft has released new fixes that supersede the original fixes for this issue. Administrators are advised to apply the new patches as they also address BID 8458, 8459, and 8460 in addition to this BID.
HP has made fixes available for OpenVMS.
Microsoft Windows NT Terminal Server 4.0 SP6
-
Microsoft Q823980i.EXE
http://microsoft.com/downloads/details.aspx?FamilyId=6C0F0160-64FA-424 C-A3C1-C9FAD2DC65CA&displaylang=en -
Microsoft Security Update for Windows NT 4.0 Terminal Server Edition (KB824146)
http://www.microsoft.com/downloads/details.aspx?FamilyId=677229F8-FBBF -4FF4-A2E9-506D17BB883F&displaylang=en
Microsoft Windows Server 2003 Standard Edition
-
Microsoft Security Update for Windows Server 2003 (KB824146)
http://www.microsoft.com/downloads/details.aspx?FamilyId=51184D09-4F7E -4F7B-87A4-C208E9BA4787&displaylang=en -
Microsoft WindowsServer2003-KB823980-x86-ENU.exe
http://microsoft.com/downloads/details.aspx?FamilyId=F8E0FF3A-9F4C-406 1-9009-3A212458E92E&displaylang=en
Microsoft Windows XP Professional
-
Microsoft Security Update for Windows XP (KB824146)
http://www.microsoft.com/downloads/details.aspx?FamilyId=5FA055AE-A1BA -4D4A-B424-95D32CFC8CBA&displaylang=en
Cisco Conference Connection
-
Cisco win-OS-Upgrade-k9.2000-2-4sr5.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/cmva-3des
Microsoft Windows NT Workstation 4.0 SP6a
-
Microsoft Q823980i.EXE
http://microsoft.com/downloads/details.aspx?FamilyId=2CC66F4E-217E-4FA 7-BDBF-DF77A0B9303F&displaylang=en -
Microsoft Security Update for Windows NT 4.0 Workstation (KB824146)
http://www.microsoft.com/downloads/details.aspx?FamilyId=7EABAD74-9CA9 -48F4-8DB5-CF8C188879DA&displaylang=en
Microsoft Windows 2000 Advanced Server SP4
-
Microsoft Security Update for Windows 2000 (KB824146)
http://www.microsoft.com/downloads/details.aspx?FamilyId=F4F66D56-E7CE -44C3-8B94-817EA8485DD1&displaylang=en -
Microsoft Windows2000-KB823980-x86-ENU.exe
http://microsoft.com/downloads/details.aspx?FamilyId=C8B8A846-F541-4C1 5-8C9F-220354449117&displaylang=en
Microsoft Windows 2000 Professional SP3
-
Microsoft Security Update for Windows 2000 (KB824146)
http://www.microsoft.com/downloads/details.aspx?FamilyId=F4F66D56-E7CE -44C3-8B94-817EA8485DD1&displaylang=en -
Microsoft Windows2000-KB823980-x86-ENU.exe
http://microsoft.com/downloads/details.aspx?FamilyId=C8B8A846-F541-4C1 5-8C9F-220354449117&displaylang=en
Microsoft Windows 2000 Professional SP2
-
Microsoft Security Update for Windows 2000 (KB824146)
http://www.microsoft.com/downloads/details.aspx?FamilyId=F4F66D56-E7CE -44C3-8B94-817EA8485DD1&displaylang=en
Microsoft Windows 2000 Advanced Server SP3
-
Microsoft Security Update for Windows 2000 (KB824146)
http://www.microsoft.com/downloads/details.aspx?FamilyId=F4F66D56-E7CE -44C3-8B94-817EA8485DD1&displaylang=en -
Microsoft Windows2000-KB823980-x86-ENU.exe
http://microsoft.com/downloads/details.aspx?FamilyId=C8B8A846-F541-4C1 5-8C9F-220354449117&displaylang=en
Microsoft Windows XP Home SP1
-
Microsoft Security Update for Windows XP (KB824146)
http://www.microsoft.com/downloads/details.aspx?FamilyId=5FA055AE-A1BA -4D4A-B424-95D32CFC8CBA&displaylang=en -
Microsoft WindowsXP-KB823980-x86-ENU.exe
http://microsoft.com/downloads/details.aspx?FamilyId=2354406C-C5B6-44A C-9532-3DE40F69C074&displaylang=en
Microsoft Windows XP 64-bit Edition
-
Microsoft Security Update for Windows XP 64-bit Edition (KB824146)
http://www.microsoft.com/downloads/details.aspx?FamilyId=50E4FB51-4E15 -4A34-9DC3-7053EC206D65&displaylang=en
Cisco IP Contact Center Express
-
Cisco win-OS-Upgrade-k9.2000-2-4sr5.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/cmva-3des
Microsoft Windows 2000 Professional SP4
-
Microsoft Security Update for Windows 2000 (KB824146)
http://www.microsoft.com/downloads/details.aspx?FamilyId=F4F66D56-E7CE -44C3-8B94-817EA8485DD1&displaylang=en -
Microsoft Windows2000-KB823980-x86-ENU.exe
http://microsoft.com/downloads/details.aspx?FamilyId=C8B8A846-F541-4C1 5-8C9F-220354449117&displaylang=en
Microsoft Windows 2000 Server SP2
-
Microsoft Security Update for Windows 2000 (KB824146)
http://www.microsoft.com/downloads/details.aspx?FamilyId=F4F66D56-E7CE -44C3-8B94-817EA8485DD1&displaylang=en
Microsoft Windows 2000 Advanced Server SP2
-
Microsoft Security Update for Windows 2000 (KB824146)
http://www.microsoft.com/downloads/details.aspx?FamilyId=F4F66D56-E7CE -44C3-8B94-817EA8485DD1&displaylang=en
Cisco Call Manager 1.0
-
Cisco win-OS-Upgrade-k9.2000-2-4sr5.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/cmva-3des
Cisco Call Manager 3.0
-
Cisco win-OS-Upgrade-k9.2000-2-4sr5.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/cmva-3des
Cisco Call Manager 3.1 (3a)
-
Cisco win-OS-Upgrade-k9.2000-2-4sr5.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/cmva-3des
Cisco Call Manager 3.1 (2)
-
Cisco win-OS-Upgrade-k9.2000-2-4sr5.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/cmva-3des
Cisco Call Manager 3.3 (3)
-
Cisco win-OS-Upgrade-k9.2000-2-4sr5.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/cmva-3des
Compaq OpenVMS 6.2 VAX
-
HP VAX_DCE_030_SSRT3608-V0100
http://www.itrc.hp.com
Compaq OpenVMS 6.2 -1H2 Alpha
-
HP ALP_DCE_030_SSRT3608-V0100
http://www.itrc.hp.com
Compaq OpenVMS 7.1 VAX
-
HP VAX_DCE_030_SSRT3608-V0100
http://www.itrc.hp.com
Compaq OpenVMS 7.1 Alpha
-
HP ALP_DCE_030_SSRT3608-V0100
http://www.itrc.hp.com
Compaq OpenVMS 7.2 Alpha
-
HP ALP_DCE_030_SSRT3608-V0100
http://www.itrc.hp.com
Compaq OpenVMS 7.2 VAX
-
HP VAX_DCE_030_SSRT3608-V0100
http://www.itrc.hp.com
Compaq OpenVMS 7.2 -1H1 Alpha
-
HP ALP_DCE_030_SSRT3608-V0100
http://www.itrc.hp.com
Compaq OpenVMS 7.2 -1H2 Alpha
-
HP ALP_DCE_030_SSRT3608-V0100
http://www.itrc.hp.com
Compaq OpenVMS 7.2 -2 Alpha
-
HP ALP_DCE_030_SSRT3608-V0100
http://www.itrc.hp.com -
HP DCOM_013_SSRT3608-V0100
http://www.itrc.hp.com
Compaq OpenVMS 7.3 Alpha
-
HP ALP_DCE_030_SSRT3608-V0100
http://www.itrc.hp.com -
HP DCOM_013_SSRT3608-V0100
http://www.itrc.hp.com
Compaq OpenVMS 7.3 -1 Alpha
-
HP ALP_DCE_030_SSRT3608-V0100
http://www.itrc.hp.com -
HP DCOM_013_SSRT3608-V0100
http://www.itrc.hp.com
References
Microsoft Windows DCOM RPC Interface Buffer Overrun Vulnerability
References:
References:
- Blaster Worm Analysis (eEye Digital Security)
- CERT Advisory CA-2003-16 Buffer Overflow in Microsoft RPC (CERT/CC)
- CERT Advisory CA-2003-20 W32/Blaster worm (CERT)
- CERT® Advisory CA-2003-19 Exploitation of Vulnerabilities in Microsoft RPC Inter (CERT)
- Cisco Security Notice: Nachi Worm Mitigation Recommendations (Cisco)
- Cisco Security Notice: W32.BLASTER Worm Mitigation Recommendations (Cisco)
- Microsoft Security Bulletin MS03-026 (Microsoft)
- MS03-026 Scanning Tool (Microsoft)
- MSRPC DCOM exploit (CORE Security)
- PSS Security Response Team Alert - New Worm: W32.Blaster.worm (Microsoft)
- Retina RPC DCOM Vulnerability Scanner (eEye Digital Security)
- Vulnerability Note VU#377804 (CERT/CC)
- KaHT II - Massive RPC Dcom exploit.. ("at4r ins4n3"
) - Re: [LSD] Critical security vulnerability in Microsoft Operating Systems (Todd Sabin
) - Re: [LSD] Critical security vulnerability in Microsoft Operating Systems (Todd Sabin
) - Re: [LSD] Critical security vulnerability in Microsoft Operating Systems (Last Stage of Delirium
) - RE: RPC DCOM still vulnerable even after applying patches ("Thor Larholm"
)