Update Protection against Microsoft Windows Workstation Service NetrGetJoinInformation Routine Memory Corruption Vulnerability (MS09-041)
| Check Point Reference: | CPAI-2009-155 | |
| Date Published: | ||
| Severity: | ||
| Last Updated: | ||
| Source: | Microsoft Security Bulletin MS09-041 | |
| Industry Reference(s): | CVE-2009-1544 | |
| Protection Provided by: |
Security Gateway
|
|
| Who is Vulnerable? Windows XP SP2 Windows XP SP3 Windows XP Professional x64 Edition SP2 Windows Server 2003 SP2 Windows Server 2003 x64 Edition SP2 Windows Server 2003 with SP2 (Itanium) Windows Vista Windows Vista SP1 Windows Vista SP2 Windows Vista x64 Edition Windows Vista x64 Edition SP1 Windows Vista x64 Edition SP2 Windows Server 2008 for 32-bit Systems Windows Server 2008 for 32-bit Systems SP2 Windows Server 2008 for x64-based Systems Windows Server 2008 for x64-based Systems SP2 Windows Server 2008 (Itanium) Windows Server 2008 (Itanium) SP2 | ||
| Vulnerability Description An elevation of privilege vulnerability has been reported in the Microsoft Windows Workstation Service. Microsoft Windows Workstation Service routes local file system requests and remote file or print network requests via Remote Procedure Call (RPC). RPC is a protocol that a program can use to request a service from another program which is located on another computer in a network. An attacker may exploit this issue to run arbitrary code with elevated privileges on an affected system. |
||
|
Update/Patch Available Apply patches: Microsoft Security Bulletin MS09-041 |
|
|
Vulnerability Details The vulnerability is due to a possible "Double Free" condition occurring in the service. The "Double Free" condition occurs when an attacker could cause an affected system, while processing a specially crafted program, to try to release or "free" memory that may have been set aside for use multiple times. Releasing memory that has already been freed could lead to memory corruption. The Windows Workstation Service fails to properly allocate and free memory when receiving specially crafted RPC messages. A remote attacker can exploit this issue by specially crafting a malicious RPC request and sending it an affected system, causing the NetrGetJoinInformation routine to incorrectly free a heap pointer. Successful exploitation may allow the attacker to take complete control of a target system. |
Protection Overview
This protection will detect and block malformed RPC requests sent to the vulnerable service.
In order for the protection to be activated, update your Security Gateway/VPN-1/InterSpect product to the latest IPS/SmartDefense update. For information on how to update IPS/SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.