Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:1883
HistoryJul 27, 2001 - 12:00 a.m.

Security Bulletin MS01-041

2001-07-2700:00:00
vulners.com
14

Title: Malformed RPC Request Can Cause Service Failure
Date: 26 July 2001
Software: Exchange Server 5.5, Exchange Server 2000,
SQL Server 7.0, SQL Server 2000, Windows NT 4.0,
Windows 2000
Impact: Denial of service
Bulletin: MS01-041

Microsoft encourages customers to review the Security Bulletin at:
http://www.microsoft.com/technet/security/bulletin/MS01-041.asp.


Issue:

Several of the RPC servers associated with system services in
Microsoft
Exchange, SQL Server, Windows NT 4.0 and Windows 2000 do not
adequately
validate inputs, and in some cases will accept invalid inputs that
prevent normal processing. The specific input values at issue here
vary
from RPC server to RPC server.

An attacker who sent such inputs to an affected RPC server could
disrupt its service. The precise type of disruption would depend on
the
specific service, but could range in effect from minor (e.g., the
service temporarily hanging) to major (e.g., the service failing in a
way that would require the entire system to be restarted).

Mitigating Factors:

  • Proper firewalling would help minimize an affected system's
    exposure to attack by Internet-based users. In general, a
    firewall should block access to all RPC services except
    those that are specifically intended for use by untrusted users.

Patch Availability:

Acknowledgment:


THE INFORMATION PROVIDED IN THE MICROSOFT KNOWLEDGE BASE IS PROVIDED
"AS IS" WITHOUT WARRANTY OF ANY KIND. MICROSOFT DISCLAIMS ALL
WARRANTIES, EITHER EXPRESS OR IMPLIED, INCLUDING THE WARRANTIES OF
MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. IN NO EVENT
SHALL
MICROSOFT CORPORATION OR ITS SUPPLIERS BE LIABLE FOR ANY DAMAGES
WHATSOEVER INCLUDING DIRECT, INDIRECT, INCIDENTAL, CONSEQUENTIAL,
LOSS
OF BUSINESS PROFITS OR SPECIAL DAMAGES, EVEN IF MICROSOFT CORPORATION
OR ITS SUPPLIERS HAVE BEEN ADVISED OF THE POSSIBILITY OF SUCH
DAMAGES.
SOME STATES DO NOT ALLOW THE EXCLUSION OR LIMITATION OF LIABILITY FOR
CONSEQUENTIAL OR INCIDENTAL DAMAGES SO THE FOREGOING LIMITATION MAY
NOT
APPLY.