Microsoft Windows Media Services Remote Denial of Service Vulnerability
BID:9825
Info
Microsoft Windows Media Services Remote Denial of Service Vulnerability
| Bugtraq ID: | 9825 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2003-0905 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 09 2004 12:00AM |
| Updated: | Jul 12 2009 03:06AM |
| Credit: | Discovery is credited to Qualys <http://www.qualys.com/>. |
| Vulnerable: |
Microsoft Windows Media Services 4.1 |
| Not Vulnerable: |
Microsoft Windows NT Terminal Server 4.0 SP6 Microsoft Windows NT Terminal Server 4.0 SP5 Microsoft Windows NT Terminal Server 4.0 SP4 Microsoft Windows NT Terminal Server 4.0 SP3 Microsoft Windows NT Terminal Server 4.0 SP2 Microsoft Windows NT Terminal Server 4.0 SP1 Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6 Microsoft Windows NT Enterprise Server 4.0 SP5 Microsoft Windows NT Enterprise Server 4.0 SP4 Microsoft Windows NT Enterprise Server 4.0 SP3 Microsoft Windows NT Enterprise Server 4.0 SP2 Microsoft Windows NT Enterprise Server 4.0 SP1 Microsoft Windows NT Enterprise Server 4.0 Microsoft Windows Media Services 9.0 Series Microsoft Windows Media Services 0 |
Discussion
Microsoft Windows Media Services Remote Denial of Service Vulnerability
It has been reported that Microsoft Windows Media Services is prone to a remote denial of service vulnerability. This may allow an attacker to cause the services to effectively deny access to legitimate users by sending specially crafted TCP/IP packets on TCP ports 7007 and/or 7778.
Microsoft Windows Media Services 4.1 included with Microsoft Windows 2000 Server Service Pack 2, Service Pack 3, and Service Pack 4 is reported to be vulnerable to this issue. Windows Media Services 4.1 for Windows NT 4.0 is not vulnerable.
It has been reported that Microsoft Windows Media Services is prone to a remote denial of service vulnerability. This may allow an attacker to cause the services to effectively deny access to legitimate users by sending specially crafted TCP/IP packets on TCP ports 7007 and/or 7778.
Microsoft Windows Media Services 4.1 included with Microsoft Windows 2000 Server Service Pack 2, Service Pack 3, and Service Pack 4 is reported to be vulnerable to this issue. Windows Media Services 4.1 for Windows NT 4.0 is not vulnerable.
Exploit / POC
Microsoft Windows Media Services Remote Denial of Service Vulnerability
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Currently we are not aware of any exploits for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution / Fix
Microsoft Windows Media Services Remote Denial of Service Vulnerability
Solution:
Microsoft has released a security bulletin MSO4-008 including fixes to address this issue. For Windows 2000 Server, this security update requires Service Pack 2 (SP2), Service Pack 3 (SP3), or Service Pack 4 (SP4):
Microsoft Windows Media Services 4.1
Solution:
Microsoft has released a security bulletin MSO4-008 including fixes to address this issue. For Windows 2000 Server, this security update requires Service Pack 2 (SP2), Service Pack 3 (SP3), or Service Pack 4 (SP4):
Microsoft Windows Media Services 4.1
-
Microsoft Security Update for Windows Media Services (KB832359)
System Requirements: Windows 2000 Service Pack 2, Windows 2000 Service Pack 3, or Windows 2000 Service Pack 4
http://www.microsoft.com/downloads/details.aspx?FamilyId=7F4C067C-5D34 -48FB-A9FA-C2200243D4D2&displaylang=en
References
Microsoft Windows Media Services Remote Denial of Service Vulnerability
References:
References:
- Microsoft Security Bulletin MS04-008 (Microsoft)