Microsoft Windows Workstation Service Remote Buffer Overflow Vulnerability
BID:9011
Info
Microsoft Windows Workstation Service Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 9011 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0812 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 11 2003 12:00AM |
| Updated: | Jul 12 2009 12:56AM |
| Credit: | Vulnerability discovery credited to eEye Digital Security. Core Security Technologies has been credited with providing the updated information about the new attack vector of sending a single UDP packet to a broadcast address to exploit all vulnerable syst |
| Vulnerable: |
Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Media Center Edition Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows XP 64-bit Edition SP1 Microsoft Windows XP 64-bit Edition Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server Cisco Voice Manager Cisco User Registration Tool Cisco uOne Enterprise Edition Cisco Unity Server 4.0 Cisco Unity Server 3.3 Cisco Unity Server 3.2 Cisco Unity Server 3.1 Cisco Unity Server 3.0 Cisco Unity Server 2.46 Cisco Unity Server 2.4 Cisco Unity Server 2.3 Cisco Unity Server 2.2 Cisco Unity Server 2.1 Cisco Unity Server 2.0 Cisco Unity Server Cisco Transport Manager Cisco Trailhead Cisco SN 5428 Storage Router SN5428-3.3.2-K9 Cisco SN 5428 Storage Router SN5428-3.3.1-K9 Cisco SN 5428 Storage Router SN5428-3.2.2-K9 Cisco SN 5428 Storage Router SN5428-3.2.1-K9 Cisco SN 5428 Storage Router SN5428-2.5.1-K9 Cisco SN 5428 Storage Router SN5428-2-3.3.2-K9 Cisco SN 5428 Storage Router SN5428-2-3.3.1-K9 Cisco SN 5420 Storage Router 1.1.3 Cisco SN 5420 Storage Router 1.1 (7) Cisco SN 5420 Storage Router 1.1 (5) Cisco SN 5420 Storage Router 1.1 (4) Cisco SN 5420 Storage Router 1.1 (3) Cisco SN 5420 Storage Router 1.1 (2) Cisco Small Network Management Solution Cisco Service Management Cisco Secure Scanner Cisco Secure Policy Manager 3.0.1 Cisco Secure Access Control Server 3.2.2 Cisco Secure Access Control Server 3.2.1 Cisco Secure Access Control Server 3.2 (1.20) Cisco Secure Access Control Server Cisco Routed Wan Management Cisco QoS Policy Manager Cisco Personal Assistant 1.4 (2) Cisco Personal Assistant 1.4 (1) Cisco Personal Assistant 1.3 (4) Cisco Personal Assistant 1.3 (3) Cisco Personal Assistant 1.3 (2) Cisco Personal Assistant 1.3 (1) Cisco Personal Assistant Cisco Networking Services for Active Directory Cisco Network Registar Cisco Media Blender Cisco Lan Management Solution Cisco IP/VC 3540 Video Rate Matching Module Cisco IP/VC 3540 Application Server Cisco IP/TV Server Cisco IP Telephony Environment Monitor Cisco IP Call Center Express (IPCC Express) Standard 3.0 Cisco IP Call Center Express (IPCC Express) Enhanced 3.0 Cisco Internet Service Node Cisco Intelligent Contact Manager 5.0 Cisco Intelligent Contact Manager Cisco E-Mail Manager Cisco Dynamic Content Adapter Cisco DOCSIS CPE Configurator Cisco Customer Response Application Server Cisco Conference Connection 1.2 Cisco Conference Connection 1.1 (1) Cisco Conference Connection Cisco Collaboration Server Cisco CiscoWorks VPN/Security Management Solution Cisco Call Manager 4.0 Cisco Call Manager 3.3 (3) Cisco Call Manager 3.3 Cisco Call Manager 3.2 Cisco Call Manager 3.1 (3a) Cisco Call Manager 3.1 (2) Cisco Call Manager 3.1 Cisco Call Manager 3.0 Cisco Call Manager 2.0 Cisco Call Manager 1.0 Cisco Call Manager Cisco Building BroadBand Service Manager Hotspot 1.0 Cisco Building Broadband Service Manager (BBSM) 5.1 Cisco Building Broadband Service Manager (BBSM) 5.0 Cisco Building Broadband Service Manager (BBSM) 4.5 Cisco Building Broadband Service Manager (BBSM) 4.4 Cisco Building Broadband Service Manager (BBSM) 4.3 Cisco Building Broadband Service Manager (BBSM) 4.2 Cisco Building Broadband Service Manager (BBSM) 4.0.1 Cisco Building Broadband Service Manager (BBSM) 3.0 Cisco Building Broadband Service Manager (BBSM) 2.5.1 Cisco Broadband Troubleshooter |
| Not Vulnerable: |
Microsoft Windows XP 64-bit Edition Version 2003 Microsoft Windows Server 2003 Web Edition Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Enterprise Edition Itanium 0 Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Datacenter Edition Itanium 0 Microsoft Windows Server 2003 Datacenter Edition Microsoft Windows NT Workstation 4.0 SP6a Microsoft Windows NT Workstation 4.0 SP6 Microsoft Windows NT Workstation 4.0 SP5 Microsoft Windows NT Workstation 4.0 SP4 Microsoft Windows NT Workstation 4.0 SP3 Microsoft Windows NT Workstation 4.0 SP2 Microsoft Windows NT Workstation 4.0 SP1 Microsoft Windows NT Workstation 4.0 Microsoft Windows NT Terminal Server 4.0 SP6 Microsoft Windows NT Terminal Server 4.0 SP5 Microsoft Windows NT Terminal Server 4.0 SP4 Microsoft Windows NT Terminal Server 4.0 SP3 Microsoft Windows NT Terminal Server 4.0 SP2 Microsoft Windows NT Terminal Server 4.0 SP1 Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6 Microsoft Windows NT Enterprise Server 4.0 SP5 Microsoft Windows NT Enterprise Server 4.0 SP4 Microsoft Windows NT Enterprise Server 4.0 SP3 Microsoft Windows NT Enterprise Server 4.0 SP2 Microsoft Windows NT Enterprise Server 4.0 SP1 Microsoft Windows NT Enterprise Server 4.0 Microsoft Windows ME |
Discussion
Microsoft Windows Workstation Service Remote Buffer Overflow Vulnerability
It has been reported that Microsoft Windows Workstation (WKSSVC.DLL) service is prone to a vulnerability that may allow a remote attacker to gain unauthorized access to a vulnerable host. The problem is in the handling of requests by the Workstation Service. The Workstation Service does not properly check bounds on remote data therefore making it possible to overwrite sensitive regions of system memory.
It has been reported that Microsoft Windows Workstation (WKSSVC.DLL) service is prone to a vulnerability that may allow a remote attacker to gain unauthorized access to a vulnerable host. The problem is in the handling of requests by the Workstation Service. The Workstation Service does not properly check bounds on remote data therefore making it possible to overwrite sensitive regions of system memory.
Exploit / POC
Microsoft Windows Workstation Service Remote Buffer Overflow Vulnerability
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Various exploits have been published, some of which are designed to target systems using NTFS filesystems and other which only affect those using FAT. The primary difference is that the exploits designed for NTFS use an undocumented Windows XP API call to log to the debug directory, which would not normally be writeable by all users.
The following exploits are designed to affect systems using FAT filesystems only:
MS03-049ex.c
o_wks.c
11.14.MS03-049-II.c
The following exploits are designed to affect systems using NTFS and FAT:
12.04.rpc_wks_bo.c
0349.cpp
An exploit that is reported to be universal for all versions of Windows XP and will work on both NTFS and FAT file systems is available (WorkstationExploit.c):
CORE has developed a working commercial exploit for their IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.
Various exploits have been published, some of which are designed to target systems using NTFS filesystems and other which only affect those using FAT. The primary difference is that the exploits designed for NTFS use an undocumented Windows XP API call to log to the debug directory, which would not normally be writeable by all users.
The following exploits are designed to affect systems using FAT filesystems only:
MS03-049ex.c
o_wks.c
11.14.MS03-049-II.c
The following exploits are designed to affect systems using NTFS and FAT:
12.04.rpc_wks_bo.c
0349.cpp
An exploit that is reported to be universal for all versions of Windows XP and will work on both NTFS and FAT file systems is available (WorkstationExploit.c):
Solution / Fix
Microsoft Windows Workstation Service Remote Buffer Overflow Vulnerability
Solution:
Microsoft has released security advisory MS03-049 to address this issue. Users are strongly advised to obtain fixes, as new attacker vectors greatly increase the speed of an attack on a targeted network.
Cisco has released a security advisory detailing affected Cisco products. See referenced advisory for details concerning obtaining fixes.
Microsoft Windows 2000 Server SP2
Microsoft Windows 2000 Advanced Server SP2
Cisco Internet Service Node
Microsoft Windows XP Professional
Cisco Conference Connection
Microsoft Windows XP 64-bit Edition SP1
Microsoft Windows 2000 Advanced Server SP4
Cisco Personal Assistant
Microsoft Windows 2000 Professional SP3
Microsoft Windows 2000 Professional SP2
Microsoft Windows 2000 Datacenter Server SP4
Microsoft Windows 2000 Advanced Server SP3
Microsoft Windows XP Home
Cisco Building BroadBand Service Manager Hotspot 1.0
Cisco Call Manager 1.0
Cisco Conference Connection 1.1 (1)
Cisco Conference Connection 1.2
Cisco Personal Assistant 1.3 (4)
Cisco Personal Assistant 1.3 (1)
Cisco Personal Assistant 1.4 (2)
Cisco Personal Assistant 1.4 (1)
Cisco Call Manager 2.0
Cisco IP Call Center Express (IPCC Express) Enhanced 3.0
Cisco IP Call Center Express (IPCC Express) Standard 3.0
Cisco Building Broadband Service Manager (BBSM) 3.0
Cisco Call Manager 3.0
Cisco Call Manager 3.1
Cisco Call Manager 3.1 (3a)
Cisco Call Manager 3.2
Cisco Call Manager 3.3 (3)
Cisco Building Broadband Service Manager (BBSM) 4.0.1
Cisco Building Broadband Service Manager (BBSM) 4.2
Cisco Building Broadband Service Manager (BBSM) 4.4
Cisco Building Broadband Service Manager (BBSM) 4.5
Cisco Building Broadband Service Manager (BBSM) 5.0
Cisco Building Broadband Service Manager (BBSM) 5.1
Solution:
Microsoft has released security advisory MS03-049 to address this issue. Users are strongly advised to obtain fixes, as new attacker vectors greatly increase the speed of an attack on a targeted network.
Cisco has released a security advisory detailing affected Cisco products. See referenced advisory for details concerning obtaining fixes.
Microsoft Windows 2000 Server SP2
-
Microsoft Windows2000-KB828749-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?FamilyId=2467FE46-D167 -479C-9638-D4D79483F261&displaylang=en
Microsoft Windows 2000 Advanced Server SP2
-
Microsoft Windows2000-KB828749-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?FamilyId=2467FE46-D167 -479C-9638-D4D79483F261&displaylang=en
Cisco Internet Service Node
-
Cisco win-OS-Upgrade-k9.2000-2-5sr4.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/bbsm52
Microsoft Windows XP Professional
-
Microsoft WindowsXP-KB828035-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?FamilyId=F02DA309-4B0A -4438-A0B9-5B67414C3833&displaylang=en
Cisco Conference Connection
-
Cisco win-OS-Upgrade-k9.2000-2-5sr4.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/bbsm52
Microsoft Windows XP 64-bit Edition SP1
-
Microsoft WindowsXP-KB828035-ia64-ENU.exe
http://www.microsoft.com/downloads/details.aspx?FamilyId=2BE95254-4C65 -4CA5-80A5-55FDF5AA2296&displaylang=en
Microsoft Windows 2000 Advanced Server SP4
-
Microsoft Windows2000-KB828749-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?FamilyId=2467FE46-D167 -479C-9638-D4D79483F261&displaylang=en
Cisco Personal Assistant
-
Cisco win-OS-Upgrade-k9.2000-2-5sr4.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/bbsm52
Microsoft Windows 2000 Professional SP3
-
Microsoft Windows2000-KB828749-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?FamilyId=2467FE46-D167 -479C-9638-D4D79483F261&displaylang=en
Microsoft Windows 2000 Professional SP2
-
Microsoft Windows2000-KB828749-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?FamilyId=2467FE46-D167 -479C-9638-D4D79483F261&displaylang=en
Microsoft Windows 2000 Datacenter Server SP4
-
Microsoft Windows2000-KB828749-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?FamilyId=2467FE46-D167 -479C-9638-D4D79483F261&displaylang=en
Microsoft Windows 2000 Advanced Server SP3
-
Microsoft Windows2000-KB828749-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?FamilyId=2467FE46-D167 -479C-9638-D4D79483F261&displaylang=en
Microsoft Windows XP Home
-
Microsoft WindowsXP-KB828035-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?FamilyId=F02DA309-4B0A -4438-A0B9-5B67414C3833&displaylang=en
Cisco Building BroadBand Service Manager Hotspot 1.0
-
Cisco HotSpot 1.0 Service Pack 1
http://www.cisco.com/pcgi-bin/tablebuild.pl/bbsmhs10
Cisco Call Manager 1.0
-
Cisco win-OS-Upgrade-k9.2000-2-5sr4.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/bbsm52
Cisco Conference Connection 1.1 (1)
-
Cisco win-OS-Upgrade-k9.2000-2-5sr4.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/bbsm52
Cisco Conference Connection 1.2
-
Cisco win-OS-Upgrade-k9.2000-2-5sr4.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/bbsm52
Cisco Personal Assistant 1.3 (4)
-
Cisco win-OS-Upgrade-k9.2000-2-5sr4.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/bbsm52
Cisco Personal Assistant 1.3 (1)
-
Cisco win-OS-Upgrade-k9.2000-2-5sr4.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/bbsm52
Cisco Personal Assistant 1.4 (2)
-
Cisco win-OS-Upgrade-k9.2000-2-5sr4.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/bbsm52
Cisco Personal Assistant 1.4 (1)
-
Cisco win-OS-Upgrade-k9.2000-2-5sr4.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/bbsm52
Cisco Call Manager 2.0
-
Cisco win-OS-Upgrade-k9.2000-2-5sr4.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/bbsm52
Cisco IP Call Center Express (IPCC Express) Enhanced 3.0
-
Cisco win-OS-Upgrade-k9.2000-2-5sr4.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/bbsm52
Cisco IP Call Center Express (IPCC Express) Standard 3.0
-
Cisco win-OS-Upgrade-k9.2000-2-5sr4.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/bbsm52
Cisco Building Broadband Service Manager (BBSM) 3.0
-
Cisco BBSM52SP2.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/bbsm52
Cisco Call Manager 3.0
-
Cisco win-OS-Upgrade-k9.2000-2-5sr4.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/bbsm52
Cisco Call Manager 3.1
-
Cisco win-OS-Upgrade-k9.2000-2-5sr4.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/bbsm52
Cisco Call Manager 3.1 (3a)
-
Cisco win-OS-Upgrade-k9.2000-2-5sr4.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/bbsm52
Cisco Call Manager 3.2
-
Cisco win-OS-Upgrade-k9.2000-2-5sr4.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/bbsm52
Cisco Call Manager 3.3 (3)
-
Cisco win-OS-Upgrade-k9.2000-2-5sr4.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/bbsm52
Cisco Building Broadband Service Manager (BBSM) 4.0.1
-
Cisco BBSM52SP2.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/bbsm52
Cisco Building Broadband Service Manager (BBSM) 4.2
-
Cisco BBSM52SP2.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/bbsm52
Cisco Building Broadband Service Manager (BBSM) 4.4
-
Cisco BBSM52SP2.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/bbsm52
Cisco Building Broadband Service Manager (BBSM) 4.5
-
Cisco BBSM52SP2.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/bbsm52
Cisco Building Broadband Service Manager (BBSM) 5.0
-
Cisco BBSM52SP2.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/bbsm52
Cisco Building Broadband Service Manager (BBSM) 5.1
-
Cisco BBSM52SP2.exe
http://www.cisco.com/pcgi-bin/tablebuild.pl/bbsm52
References
Microsoft Windows Workstation Service Remote Buffer Overflow Vulnerability
References:
References:
- CERT® Advisory CA-2003-28 Buffer Overflow in Windows Workstation Service (CERT)
- Cisco Security Advisory: Buffer Overrun in Microsoft Windows 2000 Workstation Se (Cisco)
- Microsoft Security Bulletin MS03-049 (Microsoft)
- MSRPC WKSSVC exploit (CORE Security)
- Windows Workstation Service Remote Buffer Overflow (eEye Digital Security)