(MS03-007) Unchecked Buffer In Windows Component Could Cause Server Compromise (815021)
Vulnerability Identifier: CAN-2003-0109
Discovery Date: Mar 17, 2003
Risk: Highly Critical
Vulnerability Assessment Pattern File: 008
Related Malware: AGOBOT FAMILY, BKDR_RBOT.B, BKDR_SDBOT.CC, TROJ_KAHT.A, TROJ_ROLARK.A, TROJ_WCOT.A, WORM_GAOBOT.AC, WORM_KIBUV.B, WORM_MUMU.C, WORM_NACHI.A, WORM_NACHI.B, WORM_NACHI.C, WORM_NACHI.D, WORM_NACHI.F, WORM_NACHI.G, WORM_NACHI.I, WORM_NACHI.K, WORM_RBOT.AA, WORM_RBOT.AB, WORM_RBOT.AE, WORM_RBOT.AF, WORM_RBOT.AJ, WORM_RBOT.BZ, WORM_RBOT.CC, WORM_RBOT.EM, WORM_RBOT.R, WORM_RBOT.TW, WORM_RBOT.W, WORM_RBOT.WU, WORM_RBOT.ZA, WORM_SDBOT.BV, WORM_SDBOT.CC, WORM_SDBOT.DZ, WORM_SDBOT.FB, WORM_SDBOT.FC, WORM_SDBOT.FD, WORM_SDBOT.FE, WORM_SDBOT.FQ, WORM_SDBOT.G, WORM_SDBOT.GO, WORM_SDBOT.IG, WORM_SDBOT.IY, WORM_SDBOT.JG, WORM_SDBOT.JS, WORM_SDBOT.JT, WORM_SDBOT.JY, WORM_SDBOT.K, WORM_SDBOT.KY, WORM_SDBOT.M, WORM_SDBOT.MD, WORM_SDBOT.MG, WORM_SDBOT.MH, WORM_SDBOT.PF, WORM_SDBOT.WY, WORM_SDBOT.ZY, WORM_SPYBOT.AP, WORM_SPYBOT.CG, WORM_SPYBOTER.CY, WORM_SPYBOTER.CZ
Affected Software:
Microsoft Windows 2000
Microsoft Windows NT 4.0
Microsoft Windows NT Server 4.0 Terminal Server Edition
Microsoft Windows XP
Description:
This vulnerability enables a remote attacker to execute arbitrary code through a WebDAV request to IIS 5.0. This is caused by a buffer overflow in NTDLL.DLL on Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP.
The World Wide Web Distributed Authoring and Versioning (WebDAV) is a set of extensions to the Hyper Text Transfer Protocol (HTTP) that provide a standard for editing and file management between computers on the Internet.
A vulnerability exists in an unchecked buffer in the Windows file, NTDLL.DLL. This file is involved in processing parameters coming from HTTP WebDAV requests.
Exploit Details
IMPORTANT: Users of Trend Micro PC-cillin Internet Security and Network VirusWall can protect their systems from any potential virus threats that use this exploit. Network Virus Pattern (NVP) 10118, or later, can detect this exploit at the network layer as MS03-007_WEBDAV_EXPLOIT.
This WebDAV vulnerability can be exploited by using it as an attack vector. This attack is composed of a very long parameter supplied to the WebDAV component. Due to improper bounds checking within NTDLL.DLL, this will result to a buffer overflow.
The said overflow can cause the server to crash, resulting to a denial of service. Furthermore, the attack could be crafted in such a way that an arbitrary code will be executed. The code would run with the same privilege as that of the IIS Service (i.e., Local System Privilege), allowing the attacker to perform almost anything on the compromised machine such as creating, deleting or editing files and registry entries.
Patch Information:
The patch released for these vulnerabilities cover highly critical security holes. It should be applied immediately. Access the patch and additional information in the following Microsoft page: http://www.microsoft.com/technet/security/bulletin/ms03-007.mspx
Workaround Fixes:
Network VirusWall protects customers against threats related to this vulnerability by:
Isolating machines that have not yet applied the MS03-007 security update through Vulnerability Assessment Rule 008.
Detecting malicious packets at the network layer. Network Virus Pattern (NVP) 10118 enables Network VirusWall to detect and then drop exploit packets at network layer.
Vulnerability Identifier: CAN-2003-0109
Discovery Date: Mar 17, 2003
Risk: Highly Critical
Vulnerability Assessment Pattern File: 008
Related Malware: AGOBOT FAMILY, BKDR_RBOT.B, BKDR_SDBOT.CC, TROJ_KAHT.A, TROJ_ROLARK.A, TROJ_WCOT.A, WORM_GAOBOT.AC, WORM_KIBUV.B, WORM_MUMU.C, WORM_NACHI.A, WORM_NACHI.B, WORM_NACHI.C, WORM_NACHI.D, WORM_NACHI.F, WORM_NACHI.G, WORM_NACHI.I, WORM_NACHI.K, WORM_RBOT.AA, WORM_RBOT.AB, WORM_RBOT.AE, WORM_RBOT.AF, WORM_RBOT.AJ, WORM_RBOT.BZ, WORM_RBOT.CC, WORM_RBOT.EM, WORM_RBOT.R, WORM_RBOT.TW, WORM_RBOT.W, WORM_RBOT.WU, WORM_RBOT.ZA, WORM_SDBOT.BV, WORM_SDBOT.CC, WORM_SDBOT.DZ, WORM_SDBOT.FB, WORM_SDBOT.FC, WORM_SDBOT.FD, WORM_SDBOT.FE, WORM_SDBOT.FQ, WORM_SDBOT.G, WORM_SDBOT.GO, WORM_SDBOT.IG, WORM_SDBOT.IY, WORM_SDBOT.JG, WORM_SDBOT.JS, WORM_SDBOT.JT, WORM_SDBOT.JY, WORM_SDBOT.K, WORM_SDBOT.KY, WORM_SDBOT.M, WORM_SDBOT.MD, WORM_SDBOT.MG, WORM_SDBOT.MH, WORM_SDBOT.PF, WORM_SDBOT.WY, WORM_SDBOT.ZY, WORM_SPYBOT.AP, WORM_SPYBOT.CG, WORM_SPYBOTER.CY, WORM_SPYBOTER.CZ
Affected Software:
Microsoft Windows 2000
Microsoft Windows NT 4.0
Microsoft Windows NT Server 4.0 Terminal Server Edition
Microsoft Windows XP
Description:
This vulnerability enables a remote attacker to execute arbitrary code through a WebDAV request to IIS 5.0. This is caused by a buffer overflow in NTDLL.DLL on Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP.
The World Wide Web Distributed Authoring and Versioning (WebDAV) is a set of extensions to the Hyper Text Transfer Protocol (HTTP) that provide a standard for editing and file management between computers on the Internet.
A vulnerability exists in an unchecked buffer in the Windows file, NTDLL.DLL. This file is involved in processing parameters coming from HTTP WebDAV requests.
Exploit Details
IMPORTANT: Users of Trend Micro PC-cillin Internet Security and Network VirusWall can protect their systems from any potential virus threats that use this exploit. Network Virus Pattern (NVP) 10118, or later, can detect this exploit at the network layer as MS03-007_WEBDAV_EXPLOIT.
This WebDAV vulnerability can be exploited by using it as an attack vector. This attack is composed of a very long parameter supplied to the WebDAV component. Due to improper bounds checking within NTDLL.DLL, this will result to a buffer overflow.
The said overflow can cause the server to crash, resulting to a denial of service. Furthermore, the attack could be crafted in such a way that an arbitrary code will be executed. The code would run with the same privilege as that of the IIS Service (i.e., Local System Privilege), allowing the attacker to perform almost anything on the compromised machine such as creating, deleting or editing files and registry entries.
Patch Information:
The patch released for these vulnerabilities cover highly critical security holes. It should be applied immediately. Access the patch and additional information in the following Microsoft page: http://www.microsoft.com/technet/security/bulletin/ms03-007.mspx
Workaround Fixes:
Network VirusWall protects customers against threats related to this vulnerability by:
Isolating machines that have not yet applied the MS03-007 security update through Vulnerability Assessment Rule 008.
Detecting malicious packets at the network layer. Network Virus Pattern (NVP) 10118 enables Network VirusWall to detect and then drop exploit packets at network layer.