SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

Vulnerability Note VU#827267

Microsoft Server service RPC stack buffer overflow vulnerability

Overview

A stack buffer overflow vulnerability in the Microsoft Windows Server service may allow a remote, unauthenticated attacker to execute arbitrary code with SYSTEM privileges.

I. Description

MS08-067 includes the following information about the Microsoft Server service:

    The Server service provides RPC support, file print support and named pipe sharing over the network. The Server service allows the sharing of your local resources (such as disks and printers) so that other users on the network can access them. It also allows named pipe communication between applications running on other computers and your computer, which is used for RPC.

The Microsoft Server service contains a stack buffer overflow vulnerability in the handling of Remote Procedure Call (RPC) messages.

Exploit code for this vulnerability is publicly available, and the vulnerability is being currently exploited in the wild.

II. Impact

A remote, unauthenticated attacker may be able to execute arbitrary code with SYSTEM privileges on a vulnerable system.

Certain versions of malicious code called Conficker or Downadup attempt to exploit this vulnerability.

III. Solution

Apply the updates referenced in Microsoft Security Bulletin MS08-067.

Block or Restrict Access

Block access to SMB services (139/tcp, 445/tcp) from untrusted networks such as the Internet. This and additional workarounds are provide in Microsoft Security Bulletin MS08-067.

Systems Affected

VendorStatusDate NotifiedDate Updated
Microsoft CorporationVulnerable2008-11-05

References


http://www.microsoft.com/technet/security/Bulletin/ms08-067.mspx
http://blogs.technet.com/swi/archive/2008/10/23/More-detail-about-MS08-067.aspx
http://www.microsoft.com/technet/security/bulletin/ms08-oct.mspx
http://blogs.msdn.com/sdl/archive/2008/10/22/ms08-067.aspx
https://www.securecoding.cert.org/confluence/display/seccode/FIO02-C.+Canonicalize+path+names+originating+from+untrusted+sources
https://www.securecoding.cert.org/confluence/display/seccode/STR31-C.+Guarantee+that+storage+for+strings+has+sufficient+space+for+character+data+and+the+null+terminator

Credit

Thanks to Microsoft for reporting this vulnerability.

This document was written by Will Dormann.

Other Information

Date Public:2008-10-23
Date First Published:2008-10-23
Date Last Updated:2009-11-02
CERT Advisory: 
CVE-ID(s):CVE-2008-4250
NVD-ID(s):CVE-2008-4250
US-CERT Technical Alerts:TA08-297A
Metric:88.20
Document Revision:30

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2008 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader