SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#652537

Microsoft Windows SMB packet validation vulnerability

Overview

A vulnerability in the way that Microsoft Windows handles some SMB packets could allow remote attackers to execute code of their choosing on a vulnerable system.

I. Description

The Microsoft Server Message Block (SMB), and its follow-on, Common Internet File System (CIFS), are network protocols that Windows uses to share files, printers, serial ports, and communicate between computers. A vulnerability exists in the way that the affected operating systems validate certain incoming SMB packets. Additional details about the underlying cause of the vulnerability are not known.

An unauthenticated remote attacker may be able to exploit this vulnerability by sending specially-crafted SMB packets to a vulnerable system. Microsoft reports that this vulnerability may also be exploited through a malicious web page. In this scenario, an attacker would need to trick or persuade a user into browsing the malicious web page or following a link to the malicious web page provided in an email message.

II. Impact

A remote, unauthenticated attacker could execute arbitrary code on a vulnerable system.

III. Solution

Apply a patch


Microsoft has published MS05-011 in response to this issue. Users are strongly encouraged to review this bulletin and apply the patches it refers to.

Workarounds

Filter network traffic
Microsoft Security Bulletin MS05-011 also contains recommendations about packet filtering to mitigate this issue. Users, particularly those who are affected but unable to apply the patches, are encouraged to implement these workarounds.

Systems Affected

VendorStatusDate Updated
Microsoft CorporationVulnerable8-Feb-2005

References


http://www.microsoft.com/technet/security/bulletin/ms05-011.mspx
http://secunia.com/advisories/11634/

Credit

Thanks to Microsoft Security for reporting this vulnerability. Microsoft, in turn, credits eEye Digital Security with reporting this vulnerability to them.

This document was written by Chad R Dougherty, based upon information provided by Microsoft.

Other Information

Date Public02/08/2005
Date First Published02/08/2005 06:09:24 PM
Date Last Updated05/11/2005
CERT Advisory 
CVE NameCAN-2005-0045
US-CERT Technical Alerts 
Metric27.09
Document Revision7

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Copyright 2005 Carnegie Mellon University
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader