Microsoft Windows SChannel Security Remote Code Execution Vulnerability

TITLE: Microsoft Windows SChannel Security Remote Code Execution Vulnerability
CLASS: Design Error
CVE: CVE-2007-2218

REMOTE: Yes
LOCAL: No
PUBLISHED: Jun 12 2007 12:00AM
UPDATE: Jun 18 2007 09:19PM
CREDIT: Steven of COSEINC discovered this vulnerability.
VULNERABLE:

Nortel Networks Web Centric Self-Svc VoiceXML
Nortel Networks Web Centric Self-Svc CCXML
Nortel Networks Self-Service WVADS 0
Nortel Networks Self-Service Speech Server 0
Nortel Networks Self-Service Peri Workstation 0
Nortel Networks Self-Service Peri Application 0
Nortel Networks Self-Service MPS 500 0
Nortel Networks Self-Service MPS 1000 0
Nortel Networks Self-Service MPS 100 0
Nortel Networks Multiservice Access Switch 4400
Nortel Networks Multimedia Comm MCS5100
Nortel Networks Enterprise Network Management System
Nortel Networks Contact Center Express
Nortel Networks Contact Center - TAPI Server 0
Nortel Networks Contact Center - Symposium Agent 0
Nortel Networks Contact Center
Nortel Networks Centrex IP Client Manager 8.0
Nortel Networks Centrex IP Client Manager 7.0
Nortel Networks Centrex IP Client Manager 2.5
Nortel Networks Centrex IP Client Manager 9.0
Nortel Networks CallPilot 703t
Nortel Networks CallPilot 702t
Nortel Networks CallPilot 201i
Nortel Networks CallPilot 200i
Nortel Networks CallPilot 1002rp
Microsoft Windows XP Tablet PC Edition SP2
Microsoft Windows XP Professional x64 Edition SP2
Microsoft Windows XP Professional x64 Edition
Microsoft Windows XP Professional SP2
Microsoft Windows XP Media Center Edition SP2
Microsoft Windows XP Home SP2
Microsoft Windows Server 2003 x64 SP2
Microsoft Windows Server 2003 x64 SP1
Microsoft Windows Server 2003 Web Edition SP2
Microsoft Windows Server 2003 Web Edition SP1
Microsoft Windows Server 2003 Standard Edition SP2
Microsoft Windows Server 2003 Standard Edition SP1
Microsoft Windows Server 2003 Itanium SP2
Microsoft Windows Server 2003 Itanium SP1
Microsoft Windows Server 2003 Enterprise x64 Edition SP2
Microsoft Windows Server 2003 Enterprise Edition SP1
Microsoft Windows Server 2003 Datacenter x64 Edition SP2
Microsoft Windows Server 2003 Datacenter Edition SP1
Microsoft Windows 2000 Server SP4
Microsoft Windows 2000 Professional SP4
Microsoft Windows 2000 Datacenter Server SP4
Microsoft Windows 2000 Advanced Server SP4
3DM Software Disk Management Software SP2
3DM Software Disk Management Software SP1
NOT VULNERABLE:
Microsoft Windows Vista x64 Edition 0
Microsoft Windows Vista 0

Vai alla pagina originale su Security Focus

Discussion

The Microsoft Windows Schannel security package is prone to a remote code-execution vulnerability.

This vulnerability occurs when processing and validating server-sent digital signatures by the client application.

A remote attacker could exploit this issue by convincing a victim to visit a malicious website. Remote code execution is possible, but may be extremely difficult. In most cases, denial-of-service conditions will occur.

Exploit

The following exploit is available to members of the Immunity Partner's Program:

https://www.immunityinc.com/downloads/immpartners/ms07_031.py

Solution

Solution:
Microsoft released security bulletin MS07-031 with fixes to address this issue. Please see the references for more information.


Microsoft Windows XP Media Center Edition SP2


Microsoft Windows Server 2003 Itanium SP1

Microsoft Windows 2000 Advanced Server SP4

3DM Software Disk Management Software SP2

Microsoft Windows XP Home SP2

3DM Software Disk Management Software SP1

Microsoft Windows 2000 Datacenter Server SP4

Microsoft Windows XP Tablet PC Edition SP2

Microsoft Windows Server 2003 Itanium SP2

Microsoft Windows XP Professional x64 Edition

Microsoft Windows XP Professional x64 Edition SP2

Microsoft Windows Server 2003 x64 SP1

Microsoft Windows XP Professional SP2

Microsoft Windows Server 2003 x64 SP2

Microsoft Windows 2000 Server SP4

Microsoft Windows 2000 Professional SP4

References

References:

PhpLog

BNLug Benevento Linux Users Group