Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

IPS-1 Protection for VMWare DHCP Vulnerability (DHCP Version 7)

Subscribe

Check Point Reference: CPAI-2007-203
Date Published:
Severity:
Last Updated:
Source: Secunia Advisory 26890
Industry Reference(s): CVE-2007-0063
Protection Provided by: IPS-1
  • IPS-1
Who is Vulnerable?
  • EMC VMWare ACE 1 prior to 1.0.4
  • EMC VMWare ACE 2 prior to 2.0.1
  • EMC VMWare Player 1 prior to 1.0.5
  • EMC VMWare Player 2 prior to 2.0.1
  • EMC VMWare Server 1 Prior to 1.0.4
  • EMC VMWare Workstation 6 prior to 6.0.1
  • EMC VMWare Workstation 5 prior to 5.5.5
Vulnerability Description
A vulnerability exists in the EMC VMWare DHCP service.  The service fails to properly parse UDP payloads and as a result can be exploited for arbitrary code execution.
Update/Patch Available
Patched versions of all products are available; update to the latest version of the appropriate VMWare product.

 

Vulnerability Details

The DHCP service provided by the VMWare host machine is used to assign IP addresses to hosts on a Virtual network.  This service contains a vulnerability that is observed when processing UDP datagrams.  If a UDP datagram destined for the DHCP service contains a malformed/incomplete header, an erroneous payload size calculation triggers an integer underflow.  This results in an extremely large value for the payload size that can overrun an internal UDP payload destination buffer.

Successful exploitation of this vulnerability can result in arbitrary code execution on the host machine, and granted root (Unix workstations) or SYSTEM (Windows) privilege.

It is observed that although it is theoretically possible, under certain host routing constraints, to trigger the underflow from outside of the virtual host network, it is probable that code execution is not likely, due to additional data appended to the request.

Protection Overview
The DHCP Protection Group has been augmented to detect these UDP payload anomalies on the network and trigger an alert.

To configure the defense, select your product from the list below and follow the related protection steps.

Additional Information
N/A

IPS-1

How Can I Protect My Network?
By updating the IPS-1 sensors on your network with the DHCP Protection Group, attempts to exploit this vulnerability will be detected/prevented.

How Do I Know if My Network is Under Attack?
An alert is generated from the DHCP protection group.