Overview
A buffer overflow vulnerability exists in the Win32 API libraries shipped with all versions of Microsoft Windows XP, Microsoft Windows 2000, Microsoft Windows NT 4.0, and Microsoft Windows NT 4.0 Terminal Server Edition. This vulnerability, which is being actively exploited on WebDAV-enabled IIS 5.0 servers, will allow a remote attacker to execute arbitrary code on unpatched systems. Sites running Microsoft Windows should apply a patch or disable WebDAV services as soon as possible.
Description
Microsoft Windows contains a dynamic link library (DLL) named ntdll.dll. This DLL is a core operating system component used to interact with the Windows kernel. A buffer overflow vulnerability exists in ntdll.dll, which is utilized by many different components in the Windows operating system.
|
Impact
Any attacker who can reach a vulnerable web server can gain complete control of the system and execute arbitrary code in the Local System security context. Note that this may be significantly more serious than a simple "web defacement." |
Solution
Apply a patch from your vendor
|
Workarounds Disable vulnerable service Until a patch can be applied, you may wish to disable IIS: |
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
- http://www.microsoft.com/windows2000/technologies/web/default.asp
- http://www.ietf.org/rfc/rfc2518.txt
- http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/ms03-007.asp
- http://microsoft.com/downloads/details.aspx?FamilyId=C9A38D45-5145-4844-B62E-C69D32AC929B&displaylang=en
- http://www.nextgenss.com/papers/ms03-007-ntdll.pdf
- http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/ms03-007.asp
- http://www.microsoft.com/downloads/release.asp?ReleaseID=43955
- http://support.microsoft.com/default.aspx?scid=kb;en-us;241520
- http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;326444
- http://go.microsoft.com/fwlink/?LinkId=14875
- http://support.microsoft.com/default.aspx?scid=kb;en-us;816930
- http://support.microsoft.com/default.aspx?scid=kb;en-us;260694
- http://www.lurhq.com/webdav.html
Acknowledgements
This document was written by Ian A Finlay.
Other Information
CVE IDs: | CVE-2003-0109 |
CERT Advisory: | CA-2003-09 |
Severity Metric: | 78.00 |
Date Public: | 2003-03-17 |
Date First Published: | 2003-03-17 |
Date Last Updated: | 2003-05-30 14:15 UTC |
Document Revision: | 18 |