CERT-In Vulnerability Note CIVN-2006-75
Microsoft Windows Server Service Buffer Overrun Vulnerability
Original Issue Date: August 09, 2006
Severity Rating:
High
Systems Affected
- Microsoft Windows 2000 SP4
- Microsoft Windows XP SP1 and SP2
- Microsoft Windows XP Professional x64 Edition
- Microsoft Windows Server 2003 and Microsoft Windows Server 2003 SP1
- Microsoft Windows Server 2003 and Microsoft Windows Server 2003 SP1
- Microsoft Windows Server 2003 x64 Edition
Overview
A remote code execution vulnerability has been reported in Microsoft Windows Server Service that could be exploited by attacker to take complete control of the vulnerable system.
Description
The Server service provides RPC support, file print support and named pipe sharing over the network.
The vulnerability is caused due to an unchecked buffer in server service while handling malformed requests.
The attacker could exploit this vulnerability by creating and sending specially crafted messages to a vulnerable system. The messages could then be used to execute malicious code on the vulnerable system to take complete control of the system remotely.
Workarounds
Block TCP port139 and 445 at the firewall
Use a personal firewall
Enable advanced TCP/IP filtering on systems.
Block the affected ports by using IPSec on the affected systems.
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin MS06-040
Vendor Information Microsoft
http://www.microsoft.com/technet/security/Bulletin/MS06-040.mspx
Refrences
Microsoft
http://www.microsoft.com/technet/security/Bulletin/MS06-040.mspx
FrSIRT
http://www.frsirt.com/english/advisories/2006/3210
CVE Name
CVE-2006-3439
Disclaimer The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information

Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In)
Ministry of Communications and Information Technology
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003

|