Unchecked Buffer in Microsoft RAS Phonebook
A buffer overrun condition exists in Microsoft’s RAS phonebook implementation that can compromise the affected system.
June 13, 2002
Reported June 12, 2002, byMicrosoft.
VERSIONS AFFECTED
· Microsoft Windows XP
· Microsoft Windows 2000
· Microsoft Windows NT 4.0
· Microsoft Windows NT Server 4.0 Terminal Server Edition
· Microsoft RRAS, which can be installed on NT 4.0 ServicePack 6 (SP6) or WTS SP6
DESCRIPTION
A buffer overrun condition exists in Microsoft’sRAS phonebook implementation that can compromise the affected system. If anattacker logs on to an affected server and modifies a phonebook entry usingspecially malformed data and makes a connection using this modified phonebookentry, the attacker can run the data as code by the system under LocalSystemsecurity privileges.
VENDOR RESPONSE
Thevendor, Microsoft, has released SecurityBulletin MS02-029(Unchecked Buffer in Remote Access Service Phonebook Could Lead to CodeExecution) to address this vulnerability and recommends that affected usersdownload and apply the appropriate patch mentioned in the bulletin.
CREDIT
Discovered by NextGeneration Security Software.
Read more about:
MicrosoftAbout the Author
You May Also Like