Windows SMB Server Flaws Let Remote Users Deny Service and Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1024297 |
|
SecurityTracker URL: http://securitytracker.com/id/1024297
|
|
CVE Reference:
CVE-2010-2550, CVE-2010-2551, CVE-2010-2552
(Links to External Site)
|
Date: Aug 10 2010
|
Impact:
Denial of service via network, Execution of arbitrary code via network, User access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): XP SP3, 2003 SP2, Vista SP2, 2008 SP2, 7, 2008 R2; and prior service packs
|
Description:
Several vulnerabilities were reported in Windows SMB Server. A remote user can execute arbitrary code on the target system. A remote user can cause denial of service conditions.
A remote user can send a specially crafted SMB request to trigger a buffer overflow and execute arbitrary code on the target system [CVE-2010-2550]. The code will run with the privileges of the target service. Laurent Gaffie of stratsec reported this vulnerability.
A remote user can send a specially crafted SMB request to trigger a variable validation error and cause the target system to stop responding [CVE-2010-2551]. A manual restart is required to return the system to normal operations.
A remote user can send specially crafted SMB compounded requests to trigger a variable validation error and cause the target system to stop responding [CVE-2010-2552]. A manual restart is required to return the system to normal operations. Todd Wease and Richard Johnson of Sourcefire VRT and Riku Hietamaki and Joshua Morin of Codenomicon reported this vulnerability.
|
Impact:
A remote user can execute arbitrary code on the target system.
A remote user can cause the target system to stop responding.
|
Solution:
The vendor has issued the following fixes:
Windows XP Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=6E5E16F8-C140-4A1D-B898-8417A6BFD4D8
Windows XP Professional x64 Edition Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=FD6CC359-E72E-46EC-A08B-763934E3E115
Windows Server 2003 Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=230E8559-E6DF-49D5-ACB5-B0CD4BDE0BF4
Windows Server 2003 x64 Edition Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=03804F59-748E-4832-98E4-2D88564BD10A
Windows Server 2003 with SP2 for Itanium-based Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=E4F4F8B3-7A39-4D77-A46B-02C86AD159C3
Windows Vista Service Pack 1 and Windows Vista Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=9087A3AA-AA55-41F6-8C4C-F322E4AA8681
Windows Vista x64 Edition Service Pack 1 and Windows Vista x64 Edition Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=10C9D5F1-53ED-459B-A663-E69BDB845A6B
Windows Server 2008 for 32-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=A94E2E38-116A-4B63-9328-6C33E63BBBFE
Windows Server 2008 for x64-based Systems and Windows Server 2008 for x64-based Systems Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=602DD3F6-0D09-4546-B1DB-D7B6B04EDB66
Windows Server 2008 for Itanium-based Systems and Windows Server 2008 for Itanium-based Systems Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=24D8F0A3-51A9-46C1-B870-A2239BF600E4
Windows 7 for 32-bit Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=8D58EBC4-A5F9-4318-A6F1-168C1BCDAE3C
Windows 7 for x64-based Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=AD1DDF94-D714-4B36-8256-42BF79D03A90
Windows Server 2008 R2 for x64-based Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=52642A8D-1081-4496-848E-9B03BAF3FDAC
Windows Server 2008 R2 for Itanium-based Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=783FB42C-3698-4B1D-A692-3FF319578931
A restart is required.
The Microsoft advisory is available at:
http://www.microsoft.com/technet/security/bulletin/ms10-054.mspx
|
Vendor URL: www.microsoft.com/technet/security/bulletin/ms10-054.mspx (Links to External Site)
|
Cause:
Boundary error, Input validation error, State error
|
Underlying OS:
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 10 Aug 2010 17:41:42 +0000
Subject: http://www.microsoft.com/technet/security/bulletin/ms10-054.mspx
|
Microsoft Security Bulletin MS10-054 - Critical: Vulnerabilities in SMB Server Could Allow Remote Code Execution (982214)
CVE-2010-2550
CVE-2010-2551
CVE-2010-2552
|
|