Privacy and Legal Notice

CIAC INFORMATION BULLETIN

Q-270: Vulnerability in Server Service

[Microsoft Security Bulletin MS06-040 (921883)]

August 8, 2006 19:00 GMT
[REVISED 15 Aug 2006]

PROBLEM: There is a buffer overrun in Server Service.
PLATFORM: Microsoft Windows 2000 Service Pack 4
Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service Pack 2
Microsoft Windows XP Professional x64 Edition
Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1
Microsoft Windows Server 2003 for Itanium-based Systems and Microsoft Windows Server 2003 with SP1 for Itanium-based Systems
Microsoft Windows Server 2003 x64 Edition
DAMAGE: Could allow an attacker who successfully exploited this vulnerability to take complete control of the affected system.
SOLUTION: Upgrade to the appropriate version.

VULNERABILITY
ASSESSMENT:
The risk is HIGH. Could allow an attacker who successfully exploited this vulnerability to take complete control of the affected system.

LINKS:  
  CIAC BULLETIN: http://www.ciac.org/ciac/bulletins/q-270.shtml
  ORIGINAL BULLETIN: Microsoft Security Bulletin MS06-040
  ADDITIONAL LINKS: Cisco Security Response, Document ID: 70997
http://www.cisco.com/en/US/products/ps6120/tsd_products_security_response09186a008070c75a.html
   http://www.microsoft.com/technet/security/bulletin/ms06-040.mspx
  CVE: CVE-2006-3439

REVISION HISTORY:
08/15/06 - revised to note that Microsoft has updated Caveats to reflect publication of KB921883 and revised the impact in “Workarounds” 
           section for blocking identified ports.  Also adding a link to Cisco Security Response, Document ID: 70997. 
		   



[***** Start Microsoft Security Bulletin MS06-040 (921883) *****]

Microsoft Security Bulletin MS06-040

Vulnerability in Server Service Could Allow Remote Code Execution (921883)

Published: August 8, 2006

Version: 1.0

Summary

Who Should Read this Document: Customers who use Microsoft Windows

Impact of Vulnerability: Remote Code Execution

Maximum Severity Rating: Critical

Recommendation: Customers should apply the update immediately

Security Update Replacement: None

Caveats: None

Tested Software and Security Update Download Locations:

Affected Software:

Microsoft Windows 2000 Service Pack 4 — Download the update

Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service Pack 2 — Download the update

Microsoft Windows XP Professional x64 Edition — Download the update

Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1 — Download the update

Microsoft Windows Server 2003 for Itanium-based Systems and Microsoft Windows Server 2003 with SP1 for Itanium-based Systems — Download the update

Microsoft Windows Server 2003 x64 Edition — Download the update

The software in this list has been tested to determine whether the versions are affected. Other versions either no longer include security update support or may not be affected. To determine the support life cycle for your product and version, visit the Microsoft Support Lifecycle Web site.

Note The security updates for Microsoft Windows Server 2003, Windows Server 2003 Service Pack 1, and Windows Server 2003 x64 Edition also apply to Windows Server 2003 R2.

Top of sectionTop of section

General Information

Executive Summary

Executive Summary:

This update resolves a privately disclosed vulnerability as well as additional issues discovered through internal investigations.

An attacker who successfully exploited the vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

We recommend that customers apply the update immediately

Severity Ratings and Vulnerability Identifiers:

Vulnerability Identifiers Impact of Vulnerability Windows 2000 Windows XP Service Pack 1 Windows XP Service Pack 2 Windows Server 2003 Windows Server 2003 Service Pack 1

Buffer Overrun in Server Service Vulnerability - CVE-2006-3439

Remote Code Execution

Critical

Critical

Critical

Critical

Critical

Aggregate Severity of All Vulnerabilities

 

Critical

Critical

Critical

Critical

Critical

This assessment is based on the types of systems that are affected by the vulnerability, their typical deployment patterns, and the effect that exploiting the vulnerability would have on them.

Note The security updates for Windows Server 2003, Windows Server 2003 Service Pack 1, and Windows Server 2003 x64 Edition also apply to Windows Server 2003 R2.

Note The severity ratings for non-x86 operating system versions map to the x86 operating systems versions as follows:

The Windows XP Professional x64 Edition severity rating is the same as the Windows Server 2003 Service Pack 1

The Windows Server 2003 and Windows Server 2003 Service Pack 1 for Itanium-based Systems severity rating are the same as the Windows Server 2003 severity rating.

The Windows Server 2003 x64 Edition severity rating is the same as the Windows Server 2003 Service Pack 1 severity rating.

Frequently Asked Questions (FAQ) Related to This Security Update

Vulnerability Details

Buffer Overrun in Server Service Vulnerability - CVE-2006-3439:

There is a remote code execution vulnerability in Server Service that could allow an attacker who successfully exploited this vulnerability to take complete control of the affected system.

Mitigating Factors for Buffer Overrun in Server Service Vulnerability - CVE-2006-3439:
Workarounds for Buffer Overrun in Server Service Vulnerability - CVE-2006-3439:
FAQ for Buffer Overrun in Server Service Vulnerability - CVE-2006-3439:

Security Update Information

Affected Software:

For information about the specific security update for your affected software, click the appropriate link:

Windows Server 2003 (all versions)

Windows XP (all versions)

Windows 2000 (all versions)