O-004: Microsoft Buffer Overrun in Messenger Service Could Allow Code Execution Privacy and Legal Notice

CIAC INFORMATION BULLETIN

O-004: Microsoft Buffer Overrun in Messenger Service Could Allow Code Execution

[Microsoft Security Bulletin MS03-043]

October 15, 2003 19:00 GMT
[REVISED 17 Oct 2003]
[REVISED 30 Oct 2003]

PROBLEM: A buffer overflow exists in the Messenger Service that could allow arbitrary code executionon an affected system. Note that this is not the Windows Messenger Instant Messaging Program.
SOFTWARE: MS Windows NT Workstation 4.0, Service Pack 6a
MS Windows NT Server 4.0, Service Pack 6a
MS Windows NT Server 4.0, Terminal Server Edition, Service 6
MS Windows 2000, Service Pack 2
MS Windows 2000, Service Pack 3, Service Pack 4
MS Windows XP Gold, Service Pack 1
MS Windows XP 64-bit Edition
MS Windows XP 64-bit Edition Version 2003
MS Windows Server 2003
MS Windows Server 2003 64-bit Edition
Internet Scanner XPU
System Scanner SR 3.22
Proventia A Series 22.1
RealSecure Network 22.1/2.20, 22.1
DAMAGE: An attacker would be able to run code with Local System privileges and take any action on the system, including installing programs, viewing, changing or deleting data, or creating new accounts with full privileges.
SOLUTION: Customers should disable the Messenger Service immediately and eveluate their need to deploy the patch.

VULNERABILITY
ASSESSMENT:
The risk is HIGH. The attacker could install programs, view, change, or delete data, or create new accounts with full privileges.

LINKS:  
  CIAC BULLETIN: http://www.ciac.org/ciac/bulletins/o-004.shtml
  ORIGINAL BULLETIN: http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-043.asp
  CVE/CAN: http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=
CAN-2003-0717
  ADDITIONAL LINKS: Internet Security Systems
   http://xforce.iss.net/xforce/alerts/id/156
   CERT Advisory CA-2003-27
   http://www.cert.org/advisories/CA-2003-27.html
   Symantec
   http://securityresponse.symantec.com/avcenter/security/Content/8826.html

REVISION HISTORY:
10/17/03 - updated to show that Internet Security Systems (ISS) has updated 
           packages for Internet Scanner, System Scanner, RealSecure Network and 
           Server, and Proventia; and added a link to Internet Security Systems, 
           CERT Advisory CA-2003-27, and Symantec.
	
10/30/03 - Microsoft released a revised security patch for Windows 2000, 
           Windows XP, and Windows Server 2003 to address the problem 
           described in their Knowledge Base Article #830846 where 
           installation of the previous patch may stop responding (hang). 
           The revised patch contains version 5.4.1.0 of Update.exe. 
           Version 5.4.1.0 or later versions of Update.exe no longer require 
           the Debug Programs user right.

		   
   
[***** Start MS03-043 *****]

Microsoft Security Bulletin MS03-043  

Buffer Overrun in Messenger Service Could Allow Code Execution (828035)
Issued: October 15, 2003
Version Number: 1.0 


Summary

Who Should Read This Document: Customers using Microsoft® Windows®

Impact of Vulnerability: Remote Code Execution

Maximum Severity Rating: Critical

Recommendation: Customers should disable the Messenger Service immediately and evaluate 
their need to deploy the patch

Patch Replacement: None

Caveats: None

Tested Software and Patch Download Locations: 


Affected Software: 

Non Affected Software: 

The software listed above has been tested to determine if the versions are affected. 
Other versions are no longer supported, and may or may not be affected.


Technical Details

Technical Description:

A security vulnerability exists in the Messenger Service that could allow arbitrary code 
execution on an affected system. The vulnerability results because the Messenger Service 
does not properly validate the length of a message before passing it to the allocated 
buffer.

An attacker who successfully exploited this vulnerability could be able to run code with 
Local System privileges on an affected system, or could cause the Messenger Service to 
fail. The attacker could then take any action on the system, including installing programs, 
viewing, changing or deleting data, or creating new accounts with full privileges.


Mitigating factors: 


Severity Rating:
**************************************************************
Windows NT                                        Critical 
**************************************************************
Windows Server NT 4.0 Terminal Server Edition     Critical 
**************************************************************
Windows 2000                                      Critical 
**************************************************************
Windows XP                                        Critical 
**************************************************************
Windows Server 2003                               Moderate 
**************************************************************

The above assessment is based on the types of systems affected by the vulnerability, their 
typical deployment patterns, and the effect that exploiting the vulnerability would have 
on them. 

Vulnerability identifier: CAN-2003-0717


Workarounds

Microsoft has tested the following workarounds. These workarounds will not correct the 
underlying vulnerability however they help block known attack vectors. Workarounds may 
cause a reduction in functionality in some cases – in such situations this is identified 
below.



Security Patch Information

Installation platforms and Prerequisites: 

For information about the specific security patch for your platform, click the appropriate 
link: 


Acknowledgments

Microsoft thanks the following for working with us to protect customers: 


Obtaining other security patches:

Patches for other security issues are available from the following locations: 


Support:


Security Resources: 


Disclaimer:

The information provided in the Microsoft Knowledge Base is provided "as is" without 
warranty of any kind. Microsoft disclaims all warranties, either express or implied, 
including the warranties of merchantability and fitness for a particular purpose. In no 
event shall Microsoft Corporation or its suppliers be liable for any damages whatsoever 
including direct, indirect, incidental, consequential, loss of business profits or special 
damages, even if Microsoft Corporation or its suppliers have been advised of the 
possibility of such damages. Some states do not allow the exclusion or limitation of 
liability for consequential or incidental damages so the foregoing limitation may not 
apply. 


Revisions:


[***** End MS03-043 *****]


CIAC wishes to acknowledge the contributions of Microsoft for the information contained in this bulletin.
DOE-CIRC can be contacted at:
    Voice:          +1 866-941-2472 (7 x 24)
    E-mail:          doecirc@doecirc.energy.gov
    World Wide Web:  http://www.doecirc.energy.gov/