| PROBLEM: | A buffer overflow exists in the Messenger Service that could allow arbitrary code executionon an affected system. Note that this is not the Windows Messenger Instant Messaging Program. |
| SOFTWARE: | MS Windows NT Workstation 4.0, Service Pack 6a MS Windows NT Server 4.0, Service Pack 6a MS Windows NT Server 4.0, Terminal Server Edition, Service 6 MS Windows 2000, Service Pack 2 MS Windows 2000, Service Pack 3, Service Pack 4 MS Windows XP Gold, Service Pack 1 MS Windows XP 64-bit Edition MS Windows XP 64-bit Edition Version 2003 MS Windows Server 2003 MS Windows Server 2003 64-bit Edition Internet Scanner XPU System Scanner SR 3.22 Proventia A Series 22.1 RealSecure Network 22.1/2.20, 22.1 |
| DAMAGE: | An attacker would be able to run code with Local System privileges and take any action on the system, including installing programs, viewing, changing or deleting data, or creating new accounts with full privileges. |
| SOLUTION: | Customers should disable the Messenger Service immediately and eveluate their need to deploy the patch. |
| VULNERABILITY ASSESSMENT: |
The risk is HIGH. The attacker could install programs, view, change, or delete data, or create new accounts with full privileges. |
| LINKS: | |
| CIAC BULLETIN: | http://www.ciac.org/ciac/bulletins/o-004.shtml |
| ORIGINAL BULLETIN: | http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-043.asp |
| CVE/CAN: | http://www.cve.mitre.org/cgi-bin/cvename.cgi?name= CAN-2003-0717 |
| ADDITIONAL LINKS: | Internet Security Systems |
| http://xforce.iss.net/xforce/alerts/id/156 |
|
| CERT Advisory CA-2003-27 |
|
| http://www.cert.org/advisories/CA-2003-27.html |
|
| Symantec |
|
| http://securityresponse.symantec.com/avcenter/security/Content/8826.html |
|
REVISION HISTORY:
10/17/03 - updated to show that Internet Security Systems (ISS) has updated
packages for Internet Scanner, System Scanner, RealSecure Network and
Server, and Proventia; and added a link to Internet Security Systems,
CERT Advisory CA-2003-27, and Symantec.
10/30/03 - Microsoft released a revised security patch for Windows 2000,
Windows XP, and Windows Server 2003 to address the problem
described in their Knowledge Base Article #830846 where
installation of the previous patch may stop responding (hang).
The revised patch contains version 5.4.1.0 of Update.exe.
Version 5.4.1.0 or later versions of Update.exe no longer require
the Debug Programs user right.
[***** Start MS03-043 *****]
Microsoft Security Bulletin MS03-043
Buffer Overrun in Messenger Service Could Allow Code Execution (828035)
Issued: October 15, 2003
Version Number: 1.0
Summary
Who Should Read This Document: Customers using Microsoft® Windows®
Impact of Vulnerability: Remote Code Execution
Maximum Severity Rating: Critical
Recommendation: Customers should disable the Messenger Service immediately and evaluate
their need to deploy the patch
Patch Replacement: None
Caveats: None
Tested Software and Patch Download Locations:
Affected Software:
Voice: +1 866-941-2472 (7 x 24)
E-mail: doecirc@doecirc.energy.gov
World Wide Web: http://www.doecirc.energy.gov/