Protection against Vulnerabilities in Microsoft Windows Distributed Transaction Coordinator (DTC) - MS05-051
| Attack ID: | CPAI-2005-140 |
| Publish Date: | |
| Last Update: | |
| Category: | Remote Code Execution |
| Vulnerable Systems: | Windows 2000 Professional Windows 2000 Server Windows Server 2003 Windows XP |
| Source: |
Microsoft Security Bulletin MS05-051 |
| Description: | DTC (Distributed Transaction Coordinator) is a system service that coordinates transactions. A vulnerability was detected in the DTC service for several Microsoft Windows operating systems that can allow remote attackers to execute arbitrary code via a crafted DTC packet. |
| Severity: | |
| Details: | A buffer overflow vulnerability exists in Microsoft DTC caused by improper validation of crafted DTC packets. |
| Attack Detection: | Users of VPN-1 NG with Application Intelligence R55W, VPN-1 NGX R60 and users of InterSpect who have applied the solution outlined below will identify the attack by the following log entries: Users of VPN-1 NG with Application Intelligence R55 will receive rule 99449 on the SmartView Tracker screen. |
| Solution: | Users of VPN-1 NG with Application Intelligence R55 & 55W, users of VPN-1 NGX R60 and users of InterSpect should update their SmartDefense by clicking Online Update in the SmartDashboard General window. The update blocks the specific vulnerable operation in DTC MS-RPC interface over the Common Internet File Sharing (CIFS) protocol. |
| Industry Reference: | CAN-2005-2119 |
| Additional Information: |
This update also includes: |