MS03-007 - Unchecked Buffer (WebDav Protocol-IIS)


Recommended Posts

-----BEGIN PGP SIGNED MESSAGE-----

- ----------------------------------------------------------------------

Title: Unchecked Buffer In Windows Component Could Cause

Server Compromise (815021)

Released: 17 Mar 2003

Revised: 23 Apr 2003 (version 2.0)

Software: Microsoft ® Windows ® NT 4.0 and Windows 2000

Impact: Run code of attacker's choice

Max Risk: Critical

Bulletin: MS03-007

Microsoft encourages customers to review the Security Bulletin

at: http://www.microsoft.com/technet/security/...in/MS03-007.asp

http://www.microsoft.com/security/security...ns/ms03-007.asp

- ----------------------------------------------------------------------

Reason for Revision:

====================

Microsoft originally released this security bulletin on March 17,

2003. At that time, Microsoft was aware of a publicly available

exploit that was being used to attack Windows 2000 Servers

running IIS 5.0. The attack vector in this case was WebDAV

although the underlying vulnerability was in a core operating

system component, ntdll.dll. Microsoft issued a patch to protect

Windows 2000 customers shortly afterwards, but also continued to

investigate the underlying vulnerability. Windows NT 4.0 also

contains the underlying vulnerability in ntdll.dll, however it

does not support WebDAV and therefore the known exploit was not

effective against Windows NT 4.0. Microsoft has now released a

patch for Windows NT 4.0.

Issue:

======

Microsoft Windows 2000 supports the World Wide Web Distributed

Authoring and Versioning (WebDAV) protocol. WebDAV, defined in

RFC 2518, is a set of extensions to the Hyper Text Transfer

Protocol (HTTP) that provide a standard for editing and file

management between computers on the Internet. A security

vulnerability is present in a Windows component used by WebDAV

and results because a core operating system component, ntdll.dll,

contains an unchecked buffer.

An attacker could exploit the vulnerability by sending a

specially formed HTTP request to a machine running Internet

Information Server (IIS). The request could cause the server to

fail or to execute code of the attacker's choice. The code would

run in the security context of the IIS service (which, by

default, runs in the LocalSystem context).

Although Microsoft has supplied a patch for this vulnerability

and recommends all affected customers install the patch

immediately, additional tools and preventive measures have been

provided that customers can use to block the exploitation of

this vulnerability while they are assessing the impact and

compatibility of the patch. These temporary workarounds and

tools are discussed in the "Workarounds" section in the FAQ

below.

Mitigating Factors:

====================

- -URLScan, which is a part of the IIS Lockdown Tool will block

this attack in its default configuration.

- -The vulnerability can only be exploited remotely if an attacker

can establish a web session with an affected server.

Risk Rating:

============

- Critical

Patch Availability:

===================

- A patch is available to fix this vulnerability. Please read the

Security Bulletins at

http://www.microsoft.com/technet/security/...in/ms03-007.asp

http://www.microsoft.com/security/security...ns/ms03-007.asp

for information on obtaining this patch.

- ---------------------------------------------------------------------

Edited by xStainDx
  • 1 month later...
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Anyway to download these versions without being on the Experimental builds?
    • Nothing is stopping you from continuing with your testing cadence. If updates are released every 2 weeks instead of 4, and you test once every 4 weeks, the exact same amount of patches will still be available for you in those 4 weeks. For example: Before 4th week - patch 1, 2, 3, 4 After 2nd week - patch 1 and 2 4th week - patch 3 and 4 Still the same amount after 4.
    • Everyone else has said it. I'm gonna say it - you don't know what you're talking about. I do. I have two laptops. One work, one personal. I have access to two more laptops - both personal. At home I manually update my personal laptop when I see on Neowin that there is an update - I carry on and only apply the updates when I am ready. My work one only updates when my workplace decides to send it - I carry on and only apply the updates (when they actually arrive, which is usually days after the release) when I switch off the laptop at the end of the day as usual. The two other personal laptops only get updated when I get to it which is rarely - the people who own them carry on using them until I get to it and update them. All of the browsers on all laptops are configured to restore the tabs when launched. Google and Microsoft have changed from 6 weeks to 4, and it looks like it's going to move to 2. None of these changes affect how any of these browsers on the laptops are used. Not one jot. My advice to you is stop panicking whenever you see an update. Just carry on with what you're doing. This even benefits you in a way - from your comment you sound like you don't like the changes or the frivolous new features - great - then carry on as before!
    • AMAZON needs to take total accountability for this.
    • Server Summit had a heap of announcements, ADCS changes are baller.
  • Recent Achievements

    • Week One Done
      Jeroen Wilms earned a badge
      Week One Done
    • Week One Done
      rolfus earned a badge
      Week One Done
    • One Month Later
      Leroy Jethro Gibbs earned a badge
      One Month Later
    • Conversation Starter
      flexorcist earned a badge
      Conversation Starter
    • One Month Later
      AndreaB earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      509
    2. 2
      +Edouard
      198
    3. 3
      PsYcHoKiLLa
      138
    4. 4
      ATLien_0
      90
    5. 5
      Steven P.
      80
  • Tell a friend

    Love Neowin? Tell a friend!