Vulnerability Note VU#568148
Microsoft Windows RPC vulnerable to buffer overflow
Overview
A buffer overflow vulnerability exists in Microsoft's Remote Procedure Call (RPC) implementation. A remote attacker could exploit this vulnerability to execute arbitrary code or cause a denial of service. An exploit for this vulnerability is publicly available.
Description
Microsoft describes their implementation of the RPC protocol as, "a protocol used by the Windows operating system. RPC provides an inter-process communication mechanism that allows a program running on one computer to seamlessly execute code on a remote system. The protocol itself is derived from the Open Software Foundation (OSF) RPC protocol, but with the addition of some Microsoft specific extensions." A buffer overflow has been discovered in Microsoft's RPC implementation. Quoting from Microsoft Security Bulletin MS03-026:
|
Impact
A remote attacker could exploit this vulnerability to execute arbitrary code with System Privileges or cause a denial of service. |
Solution
Apply Patch |
|
Systems Affected (Learn More)
| Vendor | Status | Date Notified | Date Updated |
|---|---|---|---|
| Microsoft Corporation | Affected | - | 16 Jul 2003 |
| Nortel Networks, Inc. | Affected | 17 Jul 2003 | 02 Aug 2003 |
CVSS Metrics (Learn More)
| Group | Score | Vector |
|---|---|---|
| Base | N/A | N/A |
| Temporal | N/A | N/A |
| Environmental | N/A | N/A |
References
- http://www.cert.org/advisories/CA-2003-19.html
- http://msdn.microsoft.com/library/default.asp?url=/library/en-us/rpc/rpc/how_rpc_works.asp
- http://msdn.microsoft.com/library/default.asp?url=/library/en-us/com/htm/comext_3aw3.asp
- http://marc.theaimsgroup.com/?l=bugtraq&m=105838687731618&w=2
- http://www.microsoft.com/technet/security/bulletin/MS03-026.asp
- https://www.securecoding.cert.org/confluence/x/aoCM
Credit
This vulnerability was discovered by The Last Stage of Delirium Research Group. Microsoft has published Microsoft Security Bulletin MS03-026 to address this vulnerability.
This document was written by Ian A Finlay and Damon G. Morda.
Other Information
- CVE IDs: CVE-2003-0352
- CERT Advisory: CA-2003-16
- Date Public: 16 Jul 2003
- Date First Published: 16 Jul 2003
- Date Last Updated: 19 Dec 2007
- Severity Metric: 78.75
- Document Revision: 27
Feedback
If you have feedback, comments, or additional information about this vulnerability, please send us email.