HOME > VULNERABILITY NOTES


   VULNERABILITY NOTES

CERT-In Vulnerability Note CIVN-2006-75
Microsoft Windows Server Service Buffer Overrun Vulnerability

Original Issue Date: August 09, 2006

Severity Rating: High

Systems Affected

  • Microsoft Windows 2000 SP4
  • Microsoft Windows XP SP1 and SP2
  • Microsoft Windows XP Professional x64 Edition
  • Microsoft Windows Server 2003 and Microsoft Windows Server 2003 SP1
  • Microsoft Windows Server 2003 and Microsoft Windows Server 2003 SP1
  • Microsoft Windows Server 2003 x64 Edition

Overview

A remote code execution vulnerability has been reported in Microsoft Windows Server Service that could be exploited by attacker to take complete control of the vulnerable system.

Description

The Server service provides RPC support, file print support and named pipe sharing over the network.

The vulnerability is caused due to an unchecked buffer in server service while handling malformed requests.

The attacker could exploit this vulnerability by creating and sending specially crafted messages to a vulnerable system. The messages could then be used to execute malicious code on the vulnerable system to take complete control of the system remotely.

Workarounds

•  Block TCP port139 and 445 at the firewall
•  Use a personal firewall
•  Enable advanced TCP/IP filtering on systems.
•  Block the affected ports by using IPSec on the affected systems.

Solution

Apply appropriate patches as mentioned in Microsoft Security Bulletin MS06-040

Vendor Information

Microsoft
http://www.microsoft.com/technet/security/Bulletin/MS06-040.mspx

Refrences

Microsoft
http://www.microsoft.com/technet/security/Bulletin/MS06-040.mspx

FrSIRT
http://www.frsirt.com/english/advisories/2006/3210

CVE Name
CVE-2006-3439

Disclaimer

The information provided herein is on "as is" basis, without warranty of any kind.

Contact Information


Phone: +91-11-24368572

Postal address

Indian Computer Emergency Response Team (CERT-In)
Ministry of Communications and Information Technology
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003