Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Preemptive Protection against Microsoft Distributed Transaction Coordinator Vulnerability (MS06-018)

Subscribe

Check Point Reference: CPAI-2006-041
Date Published:
Severity:
Last Updated:
Source: Microsoft Security Bulletin MS06-018
Industry Reference(s): CVE-2006-0034
CVE-2006-1184
Protection Provided by: VPN-1
  • NGX R61
  • NGX R60
  • NG with Application Intelligence R55W
  • NG with Application Intelligence R55
VSX
  • NGX
InterSpect
  • NGX
  • 2.0 and 1.x
Who is Vulnerable?
Microsoft Windows 2000 Service Pack 4
Microsoft Windows XP Service Pack 1 and Service Pack 2
Microsoft Windows Server 2003
Microsoft Windows Server 2003 for Itanium-based Systems
Vulnerability Description
Microsoft Distributed Transaction Coordinator (MSDTC) is a system service that coordinates transactions for Microsoft Windows platforms. A vulnerability was detected in the MDTC, allowing a remote attacker with the ability to send a crafted message to cause an affected system to stop responding.
Update/Patch Available
Apply patches:
Microsoft Security Bulletin MS06-018
Vulnerability Details
the vulnerability is caused by an uncheked buffer in the MSDTC service. By sending a specially crafted message to an affected system, a remote attacker may cause the system to stop responding.

Protection Overview
Users of VPN-1 NG with Application Intelligence R55, R55W, R60, R61 and users of InterSpect who have are preemptively protected against this vulnerability if they applied the solution outlined in CPAI-2005-140.

To configure the defense, select your product from the list below and follow the related protection steps.

VPN-1 NGX: R61, R60 & and VPN-1 NG with Application Intelligence R55W

How Can I Protect My Network?

To verify that you have applied the protection, please refer to CPAI-2005-140.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following log entries:

Attack Name:  MS-RPC over CIFS Enforcement Violation
Attack Information: MS-RPC over CIFS - Detected Microsoft DTC Vulnerability (MS05-051)

 

VPN-1 NG with Application Intelligence R55

How Can I Protect My Network?
To verify that you have applied the protection, please refer to CPAi-2005-140.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log rule 99449.

InterSpect NGX & 2.0

How Can I Protect My Network?
To verify that you have applied the protection, please refer to CPAI-2005-140.

How Do I Know if My Network is Under Attack?

SmartView Tracker will log the following entries:

Attack Name:  MS-RPC over CIFS Enforcement Violation
Attack Information: MS-RPC over CIFS - Detected Microsoft DTC Vulnerability (MS05-051)