SecurityTracker.com
Keep Track of the Latest Vulnerabilities
with SecurityTracker!
    Home    |    View Topics    |    Search    |    Contact Us    |   

SecurityTracker
Archives


 
Sign Up
Sign Up for Your FREE Weekly SecurityTracker E-mail Alert Summary
Instant Alerts
Buy our Premium Vulnerability Notification Service to receive customized, instant alerts
Affiliates
Put SecurityTracker Vulnerability Alerts on Your Web Site -- It's Free!
Partners
Become a Partner and License Our Database or Notification Service
Report a Bug
Report a vulnerability that you have found to SecurityTracker
bugs
@
securitytracker.com






Category:   Application (Firewall)  >   Microsoft Internet Connection Firewall (ICF) Vendors:   Microsoft
(Vendor Issues Fix) Windows XP Service Pack 2 Firewall Configuration Error Exposes File and Print Sharing to Remote Users
SecurityTracker Alert ID:  1012639
SecurityTracker URL:  http://securitytracker.com/id/1012639
CVE Reference:   GENERIC-MAP-NOMATCH   (Links to External Site)
Date:  Dec 20 2004
Impact:   Disclosure of system information, Disclosure of user information, Host/resource access via network
Fix Available:  Yes  Vendor Confirmed:  Yes  

Description:   A vulnerability was reported in Windows XP Service Pack 2 (SP2). A remote user can access shared folders on the target system in certain configurations.

PC-WELT reported that when XP SP2 is installed on a certain configuration, a remote user can access the shared files and printers on the target system, even though the Windows XP firewall is enabled. Other services may also be accessible, the report said.

The target system is vulnerable if it is configured to provide file and print sharing for a local network, uses a dial-up or ISDN link to access the Internet, and has Internet Connection Sharing disabled. DSL users are also affected when using an integrated modem instead of a DSL router.

The report indicates the SP2 will automatically make an exception to the XP SP2 firewall to permit connections for file and printer sharing, even if previous configurations required a firewall on the dial-up adapter. When the dial-up adapter is subsequently invoked to access the Internet, the target user's files and printers will be shared with remote users.

The original report is available at:

http://www.pcwelt.de/know-how/extras/103039/ [English]
http://www.pcwelt.de/news/sicherheit/103013/ [German]

Impact:   A remote user may be able to gain access to file and print sharing services on the target system.
Solution:   The vendor has issued a fix for Windows XP SP2, available at:

http://www.microsoft.com/downloads/details.aspx?familyid=da66a0ac-55ca-4591-b3e6-d78695899141&displaylang=en

A restart may be required after you apply this update.

The knowledge base article is available at:

http://support.microsoft.com/kb/886185

Vendor URL:  support.microsoft.com/kb/886185 (Links to External Site)
Cause:   Access control error, Configuration error
Underlying OS:   Windows (XP)

Message History:   This archive entry is a follow-up to the message listed below.
Sep 21 2004 Windows XP Service Pack 2 Firewall Configuration Error Exposes File and Print Sharing to Remote Users



 Source Message Contents

Date:  Mon, 20 Dec 2004 16:08:36 -0500
Subject:  http://support.microsoft.com/kb/886185


http://support.microsoft.com/kb/886185

> Description of the critical update for Windows Firewall "My Network (subnet) only" 
> scoping in Windows XP Service Pack 2

> Because of the way that some dialing software configures routing tables, Windows 
> Firewall in Windows XP SP2 can sometimes interpret the whole Internet to be a local 
> subnet. This can let anyone on the Internet access a Windows Firewall exception if 
> the exception is configured to use the My network (subnet) only scope option.

http://www.microsoft.com/downloads/details.aspx?familyid=da66a0ac-55ca-4591-b3e6-d78695899141&displaylang=en
 
 


Go to the Top of This SecurityTracker Archive Page





Home   |    View Topics   |    Search   |    Contact Us

Copyright 2012, SecurityGlobal.net LLC