SkipNavigation
US-CERT
American Flag
  Vulnerability
Notes
Database

Search Vulnerability Notes

Vulnerability Notes Help Information


 
 View Notes By
  Name

ID Number

CVE Name

Date Public

Date Published

Date Updated

Severity Metric



 Other Documents
  Technical Alerts

Technical Bulletins

Alerts

Security Tips

 

Vulnerability Note VU#950516

Microsoft COM+ contains a memory management flaw

Overview

Microsoft COM+ contains a vulnerability due to a memory management flaw that may allow an attacker to take complete control of an affected system.

I. Description

Microsoft gives the following definition of COM+:

    COM+ is the next step in the evolution of the Microsoft Component Object Model and Microsoft Transaction Server (MTS). COM+ handles resource management tasks, such as thread allocation and security. It automatically makes applications more scalable by providing thread pooling, object pooling, and just-in-time object activation. COM+ also helps protect the integrity of data by providing transaction support even if a transaction spans multiple databases over a network. For information about COM+, visit the following Microsoft Web site.

Microsoft COM+ contains a flaw in the process used to create and utilize memory that may allow an attacker to take complete control of a system. The attacker may be able to execute arbitrary code on the system and take control of it by sending a specially-crafted network packet to the system.

Note that Windows 2000 and Windows XP SP1 systems are primarily at risk. Windows XP SP2 and Windows Server 2003 (including SP1) are only vulnerable to a local, authenticated attacker exploiting this flaw. This vulnerability is being actively exploited.

II. Impact

A remote, unauthenticated attacker may be able to execute arbitrary code and take complete control of an affected system.

III. Solution

Apply an update

Please see Microsoft Security Bulletin MS05-051 for more information.

Systems Affected

VendorStatusDate Updated
Microsoft CorporationVulnerable11-Oct-2005

References

http://www.us-cert.gov/cas/techalerts/TA05-284A.html
http://www.microsoft.com/technet/security/Bulletin/MS05-051.mspx
http://secunia.com/advisories/17161
http://www.securityfocus.com/bid/15057
http://xforce.iss.net/xforce/xfdb/22473
http://osvdb.org/displayvuln.php?osvdb_id=19902
http://www.f-secure.com/weblog/archives/archive-122005.html#00000737

Credit

Microsoft reported this vulnerability, and in turn thank Cesar Cerrudo of Argeniss for information on the issue.

This document was written by Ken MacInnis.

Other Information

Date Public10/11/2005
Date First Published10/11/2005 05:27:51 PM
Date Last Updated12/15/2005
CERT Advisory 
CVE-ID(s)CVE-2005-1978
NVD-ID(s)CVE-2005-1978
US-CERT Technical Alerts 
Metric28.10
Document Revision12

If you have feedback, comments, or additional information about this vulnerability, please send us email.
 

 
Page Corner Image
Produced 2005 by US-CERT, a government organization
Disclaimers and copyright information
Get Adobe Reader Get Adobe Reader