Microsoft Windows SChannel Security Remote Code Execution Vulnerability
TITLE: Microsoft Windows SChannel Security Remote Code Execution Vulnerability
CLASS: Design Error
CVE: CVE-2007-2218
REMOTE: Yes
LOCAL: No
PUBLISHED: Jun 12 2007 12:00AM
UPDATE: Jun 18 2007 09:19PM
CREDIT: Steven of COSEINC discovered this vulnerability.
VULNERABLE:
Nortel Networks Web Centric Self-Svc VoiceXMLNOT VULNERABLE:
Nortel Networks Web Centric Self-Svc CCXML
Nortel Networks Self-Service WVADS 0
Nortel Networks Self-Service Speech Server 0
Nortel Networks Self-Service Peri Workstation 0
Nortel Networks Self-Service Peri Application 0
Nortel Networks Self-Service MPS 500 0
Nortel Networks Self-Service MPS 1000 0
Nortel Networks Self-Service MPS 100 0
Nortel Networks Multiservice Access Switch 4400
Nortel Networks Multimedia Comm MCS5100
Nortel Networks Enterprise Network Management System
Nortel Networks Contact Center Express
Nortel Networks Contact Center - TAPI Server 0
Nortel Networks Contact Center - Symposium Agent 0
Nortel Networks Contact Center
Nortel Networks Centrex IP Client Manager 8.0
Nortel Networks Centrex IP Client Manager 7.0
Nortel Networks Centrex IP Client Manager 2.5
Nortel Networks Centrex IP Client Manager 9.0
Nortel Networks CallPilot 703t
Nortel Networks CallPilot 702t
Nortel Networks CallPilot 201i
Nortel Networks CallPilot 200i
Nortel Networks CallPilot 1002rp
Microsoft Windows XP Tablet PC Edition SP2
Microsoft Windows XP Professional x64 Edition SP2
Microsoft Windows XP Professional x64 Edition
Microsoft Windows XP Professional SP2
Microsoft Windows XP Media Center Edition SP2
Microsoft Windows XP Home SP2
Microsoft Windows Server 2003 x64 SP2
Microsoft Windows Server 2003 x64 SP1
Microsoft Windows Server 2003 Web Edition SP2
Microsoft Windows Server 2003 Web Edition SP1
Microsoft Windows Server 2003 Standard Edition SP2
Microsoft Windows Server 2003 Standard Edition SP1
Microsoft Windows Server 2003 Itanium SP2
Microsoft Windows Server 2003 Itanium SP1
Microsoft Windows Server 2003 Enterprise x64 Edition SP2
Microsoft Windows Server 2003 Enterprise Edition SP1
Microsoft Windows Server 2003 Datacenter x64 Edition SP2
Microsoft Windows Server 2003 Datacenter Edition SP1
Microsoft Windows 2000 Server SP4
Microsoft Windows 2000 Professional SP4
Microsoft Windows 2000 Datacenter Server SP4
Microsoft Windows 2000 Advanced Server SP4
3DM Software Disk Management Software SP2
3DM Software Disk Management Software SP1
Microsoft Windows Vista x64 Edition 0
Microsoft Windows Vista 0
Vai alla pagina originale su Security Focus
Discussion
The Microsoft Windows Schannel security package is prone to a remote code-execution vulnerability.
This vulnerability occurs when processing and validating server-sent digital signatures by the client application.
A remote attacker could exploit this issue by convincing a victim to visit a malicious website. Remote code execution is possible, but may be extremely difficult. In most cases, denial-of-service conditions will occur.
Exploit
The following exploit is available to members of the Immunity Partner's Program:
https://www.immunityinc.com/downloads/immpartners/ms07_031.py
Solution
Solution:
Microsoft released security bulletin MS07-031 with fixes to address this issue. Please see the references for more information.
Microsoft Windows XP Media Center Edition SP2
- Microsoft Security Update for Windows XP (KB935840)
http://www.microsoft.com/downloads/details.aspx?FamilyId=8615e6f3-415b-4c23-ba52-7eef70a11d77&displaylang=en
Microsoft Windows Server 2003 Itanium SP1
- Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB935840)
http://www.microsoft.com/downloads/details.aspx?FamilyId=028592ff-2b69-472e-b186-bd2cc76bdfa4&displaylang=en
Microsoft Windows 2000 Advanced Server SP4
- Microsoft Security Update for Windows 2000 (KB935840)
http://www.microsoft.com/downloads/details.aspx?FamilyId=5b8e728c-cb9f-4176-93a0-bf42d6387f93&displaylang=en
3DM Software Disk Management Software SP2
Microsoft Windows XP Home SP2
- Microsoft Security Update for Windows XP (KB935840)
http://www.microsoft.com/downloads/details.aspx?FamilyId=8615e6f3-415b-4c23-ba52-7eef70a11d77&displaylang=en
3DM Software Disk Management Software SP1
Microsoft Windows 2000 Datacenter Server SP4
- Microsoft Security Update for Windows 2000 (KB935840)
http://www.microsoft.com/downloads/details.aspx?FamilyId=5b8e728c-cb9f-4176-93a0-bf42d6387f93&displaylang=en
Microsoft Windows XP Tablet PC Edition SP2
- Microsoft Security Update for Windows XP (KB935840)
http://www.microsoft.com/downloads/details.aspx?FamilyId=8615e6f3-415b-4c23-ba52-7eef70a11d77&displaylang=en
Microsoft Windows Server 2003 Itanium SP2
- Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB935840)
http://www.microsoft.com/downloads/details.aspx?FamilyId=028592ff-2b69-472e-b186-bd2cc76bdfa4&displaylang=en
Microsoft Windows XP Professional x64 Edition
- Microsoft Security Update for Windows XP x64 Edition (KB935840)
http://www.microsoft.com/downloads/details.aspx?FamilyId=7e994340-c616-4f66-845b-7eaf095e968a&displaylang=en
Microsoft Windows XP Professional x64 Edition SP2
- Microsoft Security Update for Windows XP x64 Edition (KB935840)
http://www.microsoft.com/downloads/details.aspx?FamilyId=7e994340-c616-4f66-845b-7eaf095e968a&displaylang=en
Microsoft Windows Server 2003 x64 SP1
- Microsoft Security Update for Windows Server 2003 x64 Edition (KB935840)
http://www.microsoft.com/downloads/details.aspx?FamilyId=da424772-079c-4351-9759-8886e0f1ba79&displaylang=en
Microsoft Windows XP Professional SP2
- Microsoft Security Update for Windows XP (KB935840)
http://www.microsoft.com/downloads/details.aspx?FamilyId=8615e6f3-415b-4c23-ba52-7eef70a11d77&displaylang=en
Microsoft Windows Server 2003 x64 SP2
- Microsoft Security Update for Windows Server 2003 x64 Edition (KB935840)
http://www.microsoft.com/downloads/details.aspx?FamilyId=da424772-079c-4351-9759-8886e0f1ba79&displaylang=en
Microsoft Windows 2000 Server SP4
- Microsoft Security Update for Windows 2000 (KB935840)
http://www.microsoft.com/downloads/details.aspx?FamilyId=5b8e728c-cb9f-4176-93a0-bf42d6387f93&displaylang=en
Microsoft Windows 2000 Professional SP4
- Microsoft Security Update for Windows 2000 (KB935840)
http://www.microsoft.com/downloads/details.aspx?FamilyId=5b8e728c-cb9f-4176-93a0-bf42d6387f93&displaylang=en
References
References:
- [ SECURITY ADVISORY ] Centrex IP Client Manager (CICM) response to Microsoft Jun (Nortel)
- [ SECURITY ADVISORY ] Nortel Response to Microsoft Security Bulletin MS07-031 (Nortel)
- Microsoft Homepage (Microsoft)
- Vulnerability in the Windows Schannel Security Package Could Allow Remote Code E (Microsoft)
- Vulnerability Note VU#810073 - Microsoft Windows Secure Channel integer underflo (US-CERT)
- Windows Oday release (Thomas Lim
)