| PROBLEM: | There are two new vulnerabilities in the FrontPage Server
Extensions: 1) A buffer overrun in the remote debug functionality of FrontPage Server Extensions. 2) A denial of service vulnerability in the SmartHTML interpreter. |
| PLATFORM: | Microsoft Windows 2000 Service Pack 2, Service Pack 3 Microsoft Windows XP, Microsoft Windows XP Service Pack 1 Microsoft Office XP, Microsoft Office XP Service Pack 1, Service Pack 2 Affected Components: Microsoft FrontPage Server Extensions 2000 Microsoft FrontPage Server Extensions 2000 (Shipped with Windows 2000) Microsoft FrontPage Server Extensions 2000 (Shipped with Windows XP) Microsoft FrontPage Server Extensions 2002 Microsoft SharePoint Team Services 2002 (shipped with Office XP) |
| DAMAGE: | 1) An attacker could be able to run code with Local System privileges on an affected system, could cause FrontPage Server Extensions to fail, take any action on the system, including installing programs, viewing, changing or deleting data, or creating new accounts with full privileges. 2) An attacker could cause a server running FrontPage Server Extensions to temporarily stop responding to requests. |
| SOLUTION: | Install the security update immediately. NOTE--This update replaces the security updates contained in the following bulletins: MS01-035 and MS02-053 (CIAC Bulletins L-100 M-129). |
| VULNERABILITY ASSESSMENT: |
The risk is HIGH. An attacker with the privileges to remotely access the FrontPage Server Extensions could run arbitrary code on a user's system. |
| LINKS: | |
| CIAC BULLETIN: | http://www.ciac.org/ciac/bulletins/o-024.shtml |
| ORIGINAL BULLETIN: | Microsoft Security Bulletin MS03-051 |
| http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-051.asp | |
| CVE/CAN: | http://www.cve.mitre.org/cgi-bin/cvename.cgi?name= CVE-2003-0822 CVE-2003-0824 |
REVISION HISTORY:
11/13/03 - CIAC has updated CIAC O-024 to reflect the changes in Microsoft's MS03-051,
Technical Details Section on what actions an attacker could take if they
were to successfully exploit this vulnerability.
11/17/03 - CIAC has updated CIAC O-024 to reflect the following changes in Microsoft's
MS03-051: the affected versions of Microsoft Office; Technical Details
section on what actions an attacker could take if they exploit this
vulnerability; and in the Workaround section they have removed where
customers can use IIS Lockdown Tool to disable FrontPage Server Extensions
on an IIS Server.
[***** Start MS03-051 *****]
Microsoft Security Bulletin MS03-051
Buffer Overrun in Microsoft FrontPage Server Extensions Could Allow Code
Execution (813360)
Issued: November 14, 2003
Version: 1.0
Summary
Who should read this document: Customers using Microsoft® FrontPage Server
Extensions ®
Impact of vulnerability: Remote Code Execution
Maximum Severity Rating: Critical
Recommendation: Customers should install the security update immediately
Security Update Replacement: This update replaces the security updates contained
in the following bulletins: MS01-035 and MS02-053.
Caveats: None
Tested Software and Security Update Download Locations:
Affected Software:
Voice: +1 925-422-8193 (7 x 24)
FAX: +1 925-423-8002
STU-III: +1 925-423-2604
E-mail: ciac@ciac.org
World Wide Web: http://www.ciac.org/
Anonymous FTP: ftp.ciac.org