Microsoft Windows Shell Buffer Overflows Let Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1011647 |
|
SecurityTracker URL: http://securitytracker.com/id/1011647
|
|
CVE Reference:
CVE-2004-0214
(Links to External Site)
|
Updated: May 5 2009
|
Original Entry Date: Oct 12 2004
|
Impact:
Execution of arbitrary code via network, User access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): NT 4 SP6 and SP6a, 2000 SP 3 and SP 4, and XP SP1
|
Description:
A vulnerability was reported in the Microsoft Windows shell. A remote user can execute arbitrary code.
Microsoft reported that there is a flaw in the way that the Windows Shell starts applications. The Windows Shell does not properly validate the length of a message before it passes the message to a buffer.
A remote user can create HTML that, when loaded by the target user, will trigger the flaw and execute arbitrary code on the target user's system.
Microsoft credits Yorick Koster of ITsec Security Services and Roozbeh Afrasiabi with reporting these flaws.
|
Impact:
A remote user can cause arbitrary code to be executed on the target user's system with the privileges of the target user.
|
Solution:
The vendor has issued a fix.
Microsoft Windows NT Server 4.0 Service Pack 6a:
http://www.microsoft.com/downloads/details.aspx?FamilyId=F8046E83-E151-4AAF-80CB-AD4F31C02EAC
Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack 6:
http://www.microsoft.com/downloads/details.aspx?FamilyId=2DCC6C99-509D-41A5-A3C7-CAC017D633E1
Microsoft Windows 2000 Service Pack 3 and Microsoft Windows 2000 Service Pack 4:
http://www.microsoft.com/downloads/details.aspx?FamilyId=846E7479-133B-45D7-AA69-D9257F1BE178
Microsoft Windows XP and Microsoft Windows XP Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?FamilyId=FB93CB07-3A7E-444C-B083-324FC9049B94
Microsoft Windows XP 64-Bit Edition Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?FamilyId=FF84BCBE-D1E5-4402-8CE4-F8D9966C79D0
Microsoft Windows XP 64-Bit Edition Version 2003:
http://www.microsoft.com/downloads/details.aspx?FamilyId=AB91C7FF-2547-455E-9A6D-82B09373495F
Microsoft Windows Server 2003:
http://www.microsoft.com/downloads/details.aspx?FamilyId=5C60CA12-0045-42B7-9F2A-6D433DEDC105&
Microsoft Windows Server 2003 64-Bit Edition:
http://www.microsoft.com/downloads/details.aspx?FamilyId=AB91C7FF-2547-455E-9A6D-82B09373495F
[Editor's note: Windows 2003 is not affected by this flaw, but the fix is listed above because MS04-037 fixes a separately reported vulnerability that does affected Windows 2003. A separate alert has been issued regarding that other vulnerability.]
Windows XP SP2 is not affected.
A system restart is required.
|
Vendor URL: www.microsoft.com/technet/security/bulletin/ms04-037.mspx (Links to External Site)
|
Cause:
Boundary error
|
Underlying OS:
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 12 Oct 2004 13:31:16 -0400
Subject: http://www.microsoft.com/technet/security/bulletin/ms04-037.mspx
|
MS04-037
http://www.microsoft.com/technet/security/bulletin/ms04-037.mspx
|
|