SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |    Help    |   

SecurityTracker
Archives


Welcome to SecurityTracker!
 
Click to Sign Up
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com

Sign Up!





Category:  OS (Microsoft)  >  Windows PPTP Service Vendors:  Microsoft
Microsoft PPTP Service Buffer Overflow May Let Remote Users Execute Arbitrary Code
SecurityTracker Alert ID:  1005296
CVE Reference:  GENERIC-MAP-NOMATCH   (Links to External Site)
Date:  Sep 26 2002
Impact:  Denial of service via network, Execution of arbitrary code via network, Root access via network
Version(s): Windows 2000, XP
Description:  A buffer overflow vulnerability was reported in Microsoft's point-to-point protocol (PPTP) service. A remote user can cause the system to crash and may be able to execute arbitrary code.

phion Information Technologies issued a security advisory warning of a pre-authentication buffer overflow affecting both the PPTP client and server implementation.

A remote user can send a specially crafted PPTP packet to overwrite kernel memory and crash the system. It is also possible to overwrite the EDI and EDX registers and, according to the report, potentially execute arbitrary shell code.

The vendor has reportedly been notified.

Impact:  A remote user can cause the system to crash. A remote user may be able to execute arbitrary code on the system.
Solution:  No solution was available at the time of this entry.
Vendor URL:  www.microsoft.com/technet/security/ (Links to External Site)
Cause:  Boundary error
Underlying OS:  Windows (2000), Windows (XP)
Underlying OS:  Windows (2000), Windows (XP)
Reported By:  sh@phion.com
Message History:   This archive entry has one or more follow-up message(s) listed below.
Oct 31 2002 (Microsoft Issues Fix) Microsoft PPTP Service Buffer Overflow May Let Remote Users Execute Arbitrary Code   (secnotif@microsoft.com)
The vendor has released a fix.



 Source Message Contents

Date:  Thu, 26 Sep 2002 12:43:46 +0300
From:  sh@phion.com
Subject:  Microsoft PPTP Server and Client remote vulnerability

 

phion Security Advisory 26/09/2002

Microsoft PPTP Server and Client remote vulnerability


Summary
-----------------------------

   The Microsoft PPTP Service shipping with Windows 2000 and XP contains a
   remotely exploitable pre-authentication bufferoverflow.


Affected Systems
-----------------------------

   Microsoft Windows 2000 and XP running either a PPTP Server or Client.


Impact
-----------------------------

   With a specially crafted PPTP packet it is possible to overwrite kernel
   memory.

   A DoS resulting in a lockup of the machine has been verified on
   Windows 2000 SP3 and Windows XP.

   A remote compromise should be possible deploying proper shellcode,
   as we were able to fill EDI and EDX with our data.

   Clients are vulnerable too, because the Service always listens on port
   1723 on any interface of the machine, this might be of special concern
   to DSL users which use PPTP to connect to their modem.


Solution
-----------------------------

   As a temporary solution for the Client issue, one might firewall the PPTP
   port in the Internet Connection Firewall for Windows XP.

   We dont know of any solution for Windows 2000 and Windows XP PPTP servers.

   The vendor has been informed.


Acknowledgements
-----------------------------

   The bug has been discovered by Stephan Hoffmann and Thomas Unterleitner
   on behalf of phion Information Technologies.


Contact Information
-----------------------------

   phion Information Technologies can be reached via:
      office@phion.com / http://www.phion.com

   Stephan Hoffmann can be reached via:
      sh@phion.com

   Thomas Unterleitner can be reached via:
      t.unterleitner@phion.com

References
-----------------------------

   [1] phion Information Technologies
       http://www.phion.com/

Exploit
-----------------------------

   phion Information Technologies will not provide an exploit for this issue.


Disclaimer
-----------------------------

   This advisory does not claim to be complete or to be usable for any
   purpose.

   This advisory is free for open distribution in unmodified form.

   Articles or Publications that are based on information from this advisory
   have to include link [1].

 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us   |    Help

Copyright 2002, SecurityGlobal.net LLC