|
Microsoft Windows Server Service DoS and Privilege Escalation
|
|
Secunia Advisory:
|
SA21276
|
|
|
Release Date:
|
2006-07-31
|
|
Last Update:
|
2008-05-15
|
|
Popularity:
|
13,848 views
|
|
|
Critical:
|
 Less critical
|
|
Impact:
|
Privilege escalation DoS
|
|
Where:
|
From local network
|
|
Solution Status:
|
Vendor Patch
|
|
| OS: | Microsoft Windows 2000 Advanced Server Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Professional Microsoft Windows 2000 Server Microsoft Windows Server 2003 Datacenter Edition Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Web Edition Microsoft Windows XP Home Edition Microsoft Windows XP Professional
|
|
|
Subscribe:
|
Instant alerts on relevant vulnerabilities
|
|
| CVE reference: | CVE-2006-3942 CVE-2006-4696
|
|
Description: Some vulnerabilities have been reported in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges and by malicious people to cause a DoS (Denial of Service).
1) A NULL pointer dereference error in the Server driver (srv.sys) when processing "SMB_COM_TRANSACTION" SMB messages can be exploited by sending a specially crafted SMB message with a string that is not properly NULL terminated.
Successful exploitation crashes the system.
2) An error exists within the way the Microsoft Server Service handles certain network messages. This can be exploited to execute arbitrary code by sending a specially crafted network message.
Successful exploitation may allow the execution of arbitrary code, but requires valid user credentials.
Solution: Apply patches.
Microsoft Windows 2000 SP4:
http://www.microsoft.com/downloads/de...=2998105d-6796-4e60-8c9c-e8241385f2a9
Microsoft Windows XP SP1/SP2:
http://www.microsoft.com/downloads/de...=08ab17b9-149c-44d4-96cf-87a8c6b9dc22
Microsoft Windows XP Professional x64 Edition:
http://www.microsoft.com/downloads/de...=433fd0f9-938f-432d-99d4-f41b92235dcf
Microsoft Windows Server 2003 (optionally with SP1):
http://www.microsoft.com/downloads/de...=abad4cc1-4ea6-4051-bc5a-79deb4dbe72b
Microsoft Windows Server 2003 for Itanium-based systems (optionally with SP1):
http://www.microsoft.com/downloads/de...=849eedef-332b-4792-b84e-3750d407a86f
Microsoft Windows Server 2003 x64 Edition:
http://www.microsoft.com/downloads/de...=31e448f7-298d-417c-a857-1646689e0817
Provided and/or discovered by: 1) Discovered independently by:
* Tom Cross, David Means, and Scott Warfield of ISS X-Force.
* Gerardo Richarte, Core Security Technologies.
2) The vendor credits:
* Fortinet
* Matthew Amdur, VMWare.
Changelog: 2006-08-03: Added CVE reference.
2006-08-15: Added additional information from Core Security Technologies.
2006-10-10: Added additional vulnerability and information provided by the vendor.
2006-10-11: Added link to Fortinet advisory. Added link to US-CERT.
2008-05-15: Updated Fortinet link.
Original Advisory: MS06-063 (KB923414):
http://www.microsoft.com/technet/security/Bulletin/MS06-063.mspx
ISS X-Force:
http://xforce.iss.net/xforce/alerts/id/231
Core Security Technologies:
http://www.coresecurity.com/common/showdoc.php?idx=562&idxseccion=10
MSRC Blog:
http://blogs.technet.com/msrc/archive/2006/07/28/443837.aspx
Fortinet:
http://www.fortiguardcenter.com/advisory/FGA-2006-27.html
Other References: US-CERT VU#820628:
http://www.kb.cert.org/vuls/id/820628
|
|
|
Track this Secunia Advisory
|
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.
Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.
|
|
|
About this Secunia Advisory
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|