Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Update Protection against Microsoft WINS Remote Code Execution Vulnerability (MS08-034)

Subscribe

Check Point Reference: CPAI-2008-077
Date Published:
Severity:
Last Updated:
Source: Microsoft Security Bulletin MS08-034
Industry Reference(s): CVE-2008-1451
Protection Provided by: VPN-1
  • NGX R65
  • NGX R62
  • NGX R61
  • NGX R60
VSX
  • NGX R65
InterSpect
  • NGX
Connectra
  • NGX R62
  • NGX R61
Who is Vulnerable?
Microsoft Windows 2000 Server SP4
Windows Server 2003 SP1
Windows Server 2003 SP2
Windows Server 2003 x64 Edition
Windows Server 2003 x64 Edition SP2
Windows Server 2003 SP1 (Itanium)
Windows Server 2003 SP2 (Itanium)
Vulnerability Description
A remote code execution vulnerability has been discovered in Microsoft WINS. Windows Internet Naming Service (WINS) was designed specifically to support NetBIOS over TCP/IP (NetBT), and is required for any environment in which users access resources that have NetBIOS names. A remote attacker can exploit this vulnerability to take complete control over an affected system.
Update/Patch Available
Apply patches:
Microsoft Security Bulletin MS08-034
Vulnerability Details
The vulnerability is due to an error in WINS that fails to correctly validate the origin of specifically crafted network packets. An attacker can trigger this issue by sending a specially crafted network packet to an affected WINS server. Successful exploitation of the vulnerability may allow the attacker to execute arbitrary code on the vulnerable system.

Protection Overview
By enabling this protection, SmartDefense will detect and block of malformed WINS notifications.

In order for the protection to be activated, update your VPN-1 product to the latest SmartDefense update. For information on how to update SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.

To configure the defense, select your product from the list below and follow the related protection steps.

VPN-1 NGX R65 & R62

How Can I Protect My Network?
1. In the SmartDefense tab, click Application Intelligence > Microsoft Networks > Block Microsoft WINS Remote Code Execution Vulnerability (MS08-034).
2. In the configuration pane, under Settings > Mode, check Active.
3. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Microsoft WINS Protection Violation
Attack Information: Microsoft WINS remote code execution vulnerability (MS08-034)

VPN-1 NGX R61 & R60

How Can I Protect My Network?
1. In the SmartDefense tree, click Application Intelligence > Microsoft Networks.
2. Select the following:

Block Microsoft WINS Remote Code Execution Vulnerability (MS08-034)

3. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Microsoft WINS Protection Violation
Attack Information: Microsoft WINS remote code execution vulnerability (MS08-034)

VPN-1 VSX NGX R65

How Can I Protect My Network?
1. In the SmartDefense tab, click Application Intelligence > Microsoft Networks > Block Microsoft WINS Remote Code Execution Vulnerability (MS08-034).
2. In the configuration pane, under Settings > Mode, check Active.
3. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Microsoft WINS Protection Violation
Attack Information: Microsoft WINS remote code execution vulnerability (MS08-034)

InterSpect NGX

How Can I Protect My Network?
1. In the left pane, select Profiles > Default Protection and select the SmartDefense page of the profile.
2. In the SmartDefense tree, click Application Intelligence > Microsoft Networks.
3. Select the following protection:

Block Microsoft WINS Remote Code Execution Vulnerability (MS08-034)

4. Install security policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: Microsoft WINS Protection Violation
Attack Information: Microsoft WINS remote code execution vulnerability (MS08-034)

Connectra NGX R62 & R61

How Can I Protect My Network?
1. In the left-hand menu, click Security > SmartDefense > Application Intelligence.
2. In the Dynamic Attacks pane, select the following protection:

Block Microsoft WINS Remote Code Execution Vulnerability (MS08-034)

3. Install policy on all modules.

How Do I Know if My Network is Under Attack?
Upon attack, the following entries will be logged:

Attack Name: Microsoft WINS Protection Violation
Attack Information: Microsoft WINS remote code execution vulnerability (MS08-034)