Microsoft Windows Workstation Service Buffer Overrun
| Attack ID: | CPAI-2003-42 |
| Publish Date: | |
| Last Update: | |
| Category: | Remote Code Execution |
| Vulnerable Systems: | Microsoft Windows 2000 Professional, Server SP-2, SP-3, SP-4 Microsoft Windows XP, Microsoft Windows XP SP-1 Microsoft Windows XP 64bit edition |
| Source: | eEye Digital Security |
| Description: | Remotely exploitable buffer overrun vulnerability was found in the Microsoft Windows Workstation service. This service is enabled by default on Windows 2000 and XP systems. An exploit to this vulnerability has already been released. |
| Severity: | |
| May lead to remote code execution. | |
| Details: | Buffer overrun vulnerability was discovered in the Microsoft Windows Workstation service. This vulnerability can be exploited via SMB/CIFS and may lead to remote code execution. The Workstation service is in charge of routing requests for local or remote resources (files or printers). It determines the location of these resources (local or remote) and routes the requests appropriately. The vulnerability is a buffer overrun in a logging function within a network management function in the service. By passing overly long parameters to this function, a buffer will be overrun. A specially crafted command may use this buffer overrun and cause the attacker's choice of code to be remotely executed on the victim's machine. The management function is called via a DCE-RPC interface over SMB (CIFS) protocol communication. |
| Attack Detection: | Using the SmartView Tracker identify SmartDefense drop logs with Attack Name: 'CIFS worm' and Information: 'CIFS worm pattern detected: \wkssvc' |
| Solution: | Users of FireWall-1 with NG with Application Intelligence can protect against this attack by defining a new CIFS worm catcher pattern.
Note: This pattern will block the Windows Workstation service completely and may cause severe remote file and print sharing connectivity issues. It is recommended to disable it after all nodes are patched with Microsoft patch KB828749 which solves this issue. More information is provided in Microsoft's website below. |
| Industry Reference: | |
| Additional Information: | Microsoft MS03-049 CERT advisory CA-2003-28 |