Microsoft FrontPage Server Extensions Remote Debug Buffer Overrun Vulnerability
BID:9007
Info
Microsoft FrontPage Server Extensions Remote Debug Buffer Overrun Vulnerability
| Bugtraq ID: | 9007 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0822 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 11 2003 12:00AM |
| Updated: | Jul 12 2009 12:56AM |
| Credit: | Discovery is credited to Brett Moore. |
| Vulnerable: |
Microsoft Windows XP Professional SP1 Microsoft Windows XP Home SP1 Microsoft Windows XP 64-bit Edition SP1 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft SharePoint Team Services 2002 Microsoft FrontPage Server Extensions 2002 Microsoft FrontPage Server Extensions 2000 |
| Not Vulnerable: | |
Discussion
Microsoft FrontPage Server Extensions Remote Debug Buffer Overrun Vulnerability
Microsoft FrontPage Server Extensions are prone to a remotely exploitable buffer overrun vulnerability that is exposed via remote debugging functionality. It is possible to trigger this condition with a chunked-encoded HTTP POST request. This could be exploited to execute arbitrary code on a vulnerable system with Local System privileges.
Microsoft FrontPage Server Extensions are prone to a remotely exploitable buffer overrun vulnerability that is exposed via remote debugging functionality. It is possible to trigger this condition with a chunked-encoded HTTP POST request. This could be exploited to execute arbitrary code on a vulnerable system with Local System privileges.
Exploit / POC
Microsoft FrontPage Server Extensions Remote Debug Buffer Overrun Vulnerability
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The researcher who discovered this vulnerability has developed working exploit code which is not publicly available or known to be circulating in the wild. The following proof-of-concept example was also provided:
POST /_vti_bin/_vti_aut/fp30reg.dll HTTP/1.1
Transfer-Encoding: chunked
PostLength
PostData
0
An exploit (fp30reg.c) has been developed and made available by Adik and is available below.
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
The researcher who discovered this vulnerability has developed working exploit code which is not publicly available or known to be circulating in the wild. The following proof-of-concept example was also provided:
POST /_vti_bin/_vti_aut/fp30reg.dll HTTP/1.1
Transfer-Encoding: chunked
PostLength
PostData
0
An exploit (fp30reg.c) has been developed and made available by Adik and is available below.
Solution / Fix
Microsoft FrontPage Server Extensions Remote Debug Buffer Overrun Vulnerability
Solution:
Microsoft has released updates to address this issue. It should be noted that the fix entitled "Security Update for Microsoft FrontPage Server Extensions 2000" is not yet available for download at the time of writing.
Microsoft Windows 2000 Server SP2
Microsoft Windows 2000 Server SP3
Microsoft Windows 2000 Advanced Server SP3
Microsoft SharePoint Team Services 2002
Microsoft FrontPage Server Extensions 2002
Microsoft Windows XP Home SP1
Microsoft FrontPage Server Extensions 2000
Microsoft Windows 2000 Professional SP3
Microsoft Windows 2000 Advanced Server SP2
Microsoft Windows 2000 Professional SP2
Microsoft Windows XP Professional SP1
Solution:
Microsoft has released updates to address this issue. It should be noted that the fix entitled "Security Update for Microsoft FrontPage Server Extensions 2000" is not yet available for download at the time of writing.
Microsoft Windows 2000 Server SP2
-
Microsoft Security Update for Windows 2000: KB810217
Microsoft FrontPage Server Extensions 2000 (Shipped with Windows 2000)
http://www.microsoft.com/downloads/details.aspx?FamilyId=057D5F0E-0E2B -47D2-9F0F-3B15DD8622A2&displaylang=en
Microsoft Windows 2000 Server SP3
-
Microsoft Security Update for Windows 2000: KB810217
Microsoft FrontPage Server Extensions 2000 (Shipped with Windows 2000)
http://www.microsoft.com/downloads/details.aspx?FamilyId=057D5F0E-0E2B -47D2-9F0F-3B15DD8622A2&displaylang=en
Microsoft Windows 2000 Advanced Server SP3
-
Microsoft Security Update for Windows 2000: KB810217
Microsoft FrontPage Server Extensions 2000 (Shipped with Windows 2000)
http://www.microsoft.com/downloads/details.aspx?FamilyId=057D5F0E-0E2B -47D2-9F0F-3B15DD8622A2&displaylang=en
Microsoft SharePoint Team Services 2002
-
Microsoft Office XP Web Services Security Patch: KB812708
Microsoft SharePoint Team Services 2002 (shipped with Office XP)
http://www.microsoft.com/downloads/details.aspx?FamilyId=5923FC2F-D786 -4E32-8F15-36A1C9E0A340&displaylang=en
Microsoft FrontPage Server Extensions 2002
-
Microsoft FrontPage 2002 Server Extensions Security Patch: KB813380
Microsoft FrontPage Server Extensions 2002
http://www.microsoft.com/downloads/details.aspx?FamilyId=3E8A21D9-708E -4E69-8299-86C49321EE25&displaylang=en
Microsoft Windows XP Home SP1
-
Microsoft Security Update for Windows XP: KB810217
Microsoft FrontPage Server Extensions 2000 (Shipped with Windows XP)
http://www.microsoft.com/downloads/details.aspx?FamilyId=9B302532-BFAB -489B-82DC-ED1E49A16E1C&displaylang=en
Microsoft FrontPage Server Extensions 2000
-
Microsoft Security Update for Microsoft FrontPage Server Extensions 2000
Microsoft FrontPage Server Extensions 2000
http://www.microsoft.com/downloads/details.aspx?FamilyId=C84C3D10-A821 -4819-BF58-D3BC70A77BFA&displaylang=en
Microsoft Windows 2000 Professional SP3
-
Microsoft Security Update for Windows 2000: KB810217
Microsoft FrontPage Server Extensions 2000 (Shipped with Windows 2000)
http://www.microsoft.com/downloads/details.aspx?FamilyId=057D5F0E-0E2B -47D2-9F0F-3B15DD8622A2&displaylang=en
Microsoft Windows 2000 Advanced Server SP2
-
Microsoft Security Update for Windows 2000: KB810217
Microsoft FrontPage Server Extensions 2000 (Shipped with Windows 2000)
http://www.microsoft.com/downloads/details.aspx?FamilyId=057D5F0E-0E2B -47D2-9F0F-3B15DD8622A2&displaylang=en
Microsoft Windows 2000 Professional SP2
-
Microsoft Security Update for Windows 2000: KB810217
Microsoft FrontPage Server Extensions 2000 (Shipped with Windows 2000)
http://www.microsoft.com/downloads/details.aspx?FamilyId=057D5F0E-0E2B -47D2-9F0F-3B15DD8622A2&displaylang=en
Microsoft Windows XP Professional SP1
-
Microsoft Security Update for Windows XP: KB810217
Microsoft FrontPage Server Extensions 2000 (Shipped with Windows XP)
http://www.microsoft.com/downloads/details.aspx?FamilyId=9B302532-BFAB -489B-82DC-ED1E49A16E1C&displaylang=en
References
Microsoft FrontPage Server Extensions Remote Debug Buffer Overrun Vulnerability
References:
References:
- IIS FrontPage Extensions exploit (CORE Security)
- Microsoft Security Bulletin MS03-051 (Microsoft)
- Frontpage Extensions Remote Command Execution ("Brett Moore"
)