SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#233754

Microsoft Windows does not adequately validate IP options

Overview

Microsoft Windows does not adequately validate IP options, allowing an unauthenticated, remote attacker to execute arbitrary code or cause a denial of service. An attacker could take complete control of a vulnerable system.

I. Description

Several versions of the Microsoft Windows IP stack are vulnerable to specially crafted packets that contain malformed IP options. When processing such a packet, a vulnerable IP stack may initially validate the options and pass them to code that uses the options data in ways that corrupt memory. Routers may drop packets with malformed IP options, so an attacker may need to be able to send packets from the same IP subnet as the target system. IP tunnels (VPNs, GRE) may deliver malformed packets through a router that would otherwise drop them.

II. Impact

An unauthenticated, remote attacker could execute arbitrary code or cause a denial of service. Since the IP stack is implemented as a kernel driver, an attacker who successfully executes arbitrary code could gain complete control of a vulnerable system. Kernel memory corruption caused by an attack could cause a vulnerable system to crash and possibly reboot.

III. Solution

Apply a patch

Apply the appropriate patch (893066) referenced by Microsoft Security Bulletin MS05-019. Microsoft Knowledge Base Article 893066 describes several issues related to the patch, including possible degraded network performance (890345).

Filter packets with malformed IP options

Filter packets with malformed IP options at network borders.

Systems Affected

VendorStatusDate Updated
Microsoft CorporationVulnerable12-Apr-2005

References

http://www.us-cert.gov/cas/alerts/SA05-102A.html
http://www.us-cert.gov/cas/alerts/TA05-102A.html
http://www.microsoft.com/technet/security/Bulletin/MS05-019.mspx
http://xforce.iss.net/xforce/alerts/id/192
http://www.iana.org/assignments/ip-parameters
http://www.securityfocus.com/bid/13116/
http://secunia.com/advisories/14512/
http://securitytracker.com/alerts/2005/Apr/1013686.html

Credit

This vulnerability was reported by Microsoft, who credits ISS X-Force.

This document was written by Art Manion.

Other Information

Date Public04/12/2005
Date First Published04/12/2005 07:27:06 PM
Date Last Updated05/03/2005
CERT Advisory 
CVE NameCAN-2005-0048
US-CERT Technical Alerts 
Metric12.29
Document Revision10

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2005 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader