Microsoft ISA Server 2000 H.323 Filter Remote Buffer Overflow Vulnerability
BID:9408
Info
Microsoft ISA Server 2000 H.323 Filter Remote Buffer Overflow Vulnerability
| Bugtraq ID: | 9408 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2003-0819 |
| Remote: | Yes |
| Local: | No |
| Published: | Jan 13 2004 12:00AM |
| Updated: | Jul 12 2009 02:06AM |
| Credit: | The disclosure of this issue has been credited to the University of Oulu Security Programming Group. |
| Vulnerable: |
Microsoft Small Business Server 2003 Microsoft Small Business Server 2000 0 Microsoft ISA Server 2000 SP1 Microsoft ISA Server 2000 FP1 Microsoft ISA Server 2000 |
| Not Vulnerable: |
Microsoft Proxy Server 2.0 SP1 Microsoft Proxy Server 2.0 |
Discussion
Microsoft ISA Server 2000 H.323 Filter Remote Buffer Overflow Vulnerability
It has been reported that the H.323 filter used by Microsoft ISA Server 2000 is prone to a remote buffer overflow vulnerability. The condition presents itself due to insufficient boundary checks performed by the Microsoft Firewall Service on specially crafted H.323 traffic.
Successful exploitation of this vulnerability may allow a remote attacker to execute arbitrary code in the context of Microsoft Firewall Service running on ISA Server 2000. This may lead to complete control of the vulnerable system.
It has been reported that the H.323 filter used by Microsoft ISA Server 2000 is prone to a remote buffer overflow vulnerability. The condition presents itself due to insufficient boundary checks performed by the Microsoft Firewall Service on specially crafted H.323 traffic.
Successful exploitation of this vulnerability may allow a remote attacker to execute arbitrary code in the context of Microsoft Firewall Service running on ISA Server 2000. This may lead to complete control of the vulnerable system.
Exploit / POC
Microsoft ISA Server 2000 H.323 Filter Remote Buffer Overflow Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft ISA Server 2000 H.323 Filter Remote Buffer Overflow Vulnerability
Solution:
Microsoft has released security advisory MS04-001 to address this issue. Users are strongly advised to obtain fixes.
Microsoft Small Business Server 2000 0
Microsoft Small Business Server 2003
Microsoft ISA Server 2000 SP1
Solution:
Microsoft has released security advisory MS04-001 to address this issue. Users are strongly advised to obtain fixes.
Microsoft Small Business Server 2000 0
-
Microsoft Vulnerability in H.323 Filter can cause Remote Code Execution (816458)
http://www.microsoft.com/downloads/details.aspx?FamilyId=CBE42990-4156 -4E1D-9ACB-4CD449D9599B&displaylang=en
Microsoft Small Business Server 2003
-
Microsoft Vulnerability in H.323 Filter can cause Remote Code Execution (816458)
http://www.microsoft.com/downloads/details.aspx?FamilyId=CBE42990-4156 -4E1D-9ACB-4CD449D9599B&displaylang=en
Microsoft ISA Server 2000 SP1
-
Microsoft Vulnerability in H.323 Filter can cause Remote Code Execution (816458)
http://www.microsoft.com/downloads/details.aspx?FamilyId=CBE42990-4156 -4E1D-9ACB-4CD449D9599B&displaylang=en
References
Microsoft ISA Server 2000 H.323 Filter Remote Buffer Overflow Vulnerability
References:
References:
- Microsoft Security Bulletin MS04-001 (Microsoft)