exploit the possibilities

ms01-041

ms01-041
Posted Jul 27, 2001

Microsoft Security Advisory MS01-041 - Several of the RPC servers associated with system services in Microsoft Exchange, SQL Server, Windows NT 4.0 and Windows 2000 do not adequately validate inputs, and are vulnerable to a remote denial of service attack. Microsoft FAQ on this issue available here.

tags | remote, denial of service
systems | windows, 2k, nt
MD5 | 2dbadf85c2999484c24b1f032a0cc16c

ms01-041

Change Mirror Download

-----BEGIN PGP SIGNED MESSAGE-----

- ----------------------------------------------------------------------
Title: Malformed RPC Request Can Cause Service Failure
Date: 26 July 2001
Software: Exchange Server 5.5, Exchange Server 2000,
SQL Server 7.0, SQL Server 2000, Windows NT 4.0,
Windows 2000
Impact: Denial of service
Bulletin: MS01-041

Microsoft encourages customers to review the Security Bulletin at:
http://www.microsoft.com/technet/security/bulletin/MS01-041.asp.
- ----------------------------------------------------------------------

Issue:
======
Several of the RPC servers associated with system services in
Microsoft
Exchange, SQL Server, Windows NT 4.0 and Windows 2000 do not
adequately
validate inputs, and in some cases will accept invalid inputs that
prevent normal processing. The specific input values at issue here
vary
from RPC server to RPC server.

An attacker who sent such inputs to an affected RPC server could
disrupt its service. The precise type of disruption would depend on
the
specific service, but could range in effect from minor (e.g., the
service temporarily hanging) to major (e.g., the service failing in a
way that would require the entire system to be restarted).

Mitigating Factors:
====================
- Proper firewalling would help minimize an affected system's
exposure to attack by Internet-based users. In general, a
firewall should block access to all RPC services except
those that are specifically intended for use by untrusted users.

Patch Availability:
===================
- A patch is available to fix this vulnerability. Please read the
Security Bulletin
http://www.microsoft.com/technet/security/bulletin/ms01-041.asp
for information on obtaining this patch.

Acknowledgment:
===============
- Bindview's Razor Team (http://razor.bindview.com)

- ---------------------------------------------------------------------

THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE BASE IS PROVIDED
"AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS ALL
WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING THE WARRANTIES OF
MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. IN NO EVENT
SHALL
MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE FOR ANY DAMAGES
WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL,
LOSS
OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF MICROSOFT CORPORATION
OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH
DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR
CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING LIMITATION MAY
NOT
APPLY.



-----BEGIN PGP SIGNATURE-----
Version: PGP Personal Privacy 6.5.3

iQEVAwUBO2CYdY0ZSRQxA/UrAQFskQgAhCSiUL+P1jGqprMKaymZ4o7Pe6MtXR+S
7GaVkXvTDKzOGwvIw23lOsR3G5d+TJUtNxpVBQwOJus82Es6rpJWjcCYzg4evZgv
wAy68V2dxNbTgk7sEKgIAUwkDGETiKONj5EyEIQfeC/UePXZmtGhzBKAmtXPmYL/
me5TNmWOwu6398OnTKBD4JC2raUpbdXEQ6/OSHAQJiUTEObhOE8ZnrxZ0ZHjsD9S
/Hw7XONVJ597mOkW3VtucH7ztKoUAvp5tkE3pwS2nKrRtT/9qatD9m18+J56PeMA
7K283xP4ILs/SQjJRwYbCL+IxnUrFi5nvAPL3y2xr9XRa4p8nxCBkg==
=GuBL
-----END PGP SIGNATURE-----

Comments

RSS Feed Subscribe to this comment feed

No comments yet, be the first!

Login or Register to post a comment

File Archive:

July 2019

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    34 Files
  • 2
    Jul 2nd
    15 Files
  • 3
    Jul 3rd
    9 Files
  • 4
    Jul 4th
    8 Files
  • 5
    Jul 5th
    2 Files
  • 6
    Jul 6th
    3 Files
  • 7
    Jul 7th
    1 Files
  • 8
    Jul 8th
    15 Files
  • 9
    Jul 9th
    15 Files
  • 10
    Jul 10th
    20 Files
  • 11
    Jul 11th
    17 Files
  • 12
    Jul 12th
    16 Files
  • 13
    Jul 13th
    2 Files
  • 14
    Jul 14th
    1 Files
  • 15
    Jul 15th
    20 Files
  • 16
    Jul 16th
    27 Files
  • 17
    Jul 17th
    7 Files
  • 18
    Jul 18th
    5 Files
  • 19
    Jul 19th
    12 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2019 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close