Update Protection against Host Integration Server RPC Buffer Overflow Vulnerability (MS08-059)
| Check Point Reference: | CPAI-2008-149 | |
| Date Published: | ||
| Severity: | ||
| Last Updated: | ||
| Source: | Microsoft Security Bulletin MS08-059 | |
| Industry Reference(s): | CVE-2008-3466 | |
| Protection Provided by: |
VPN-1
|
|
| Who is Vulnerable? Microsoft Host Integration Server 2000 SP2 Microsoft Host Integration Server 2004 Microsoft Host Integration Server 2004 SP1 Microsoft Host Integration Server 2006 | ||
| Vulnerability Description A remote code execution vulnerability has been reported in the SNA Remote Procedure Call (RPC) service for Host Integration Server. Remote Procedure Call (RPC) is a protocol that a program can use to request a service from another program which is located on another computer in a network. Microsoft Host Integration Server (HIS) is a gateway application that provides host access and integration, extending Microsoft Windows to other systems by integrating mission-critical host applications, data sources, messaging, and security systems. An attacker may exploit this issue to take complete control of an affected system. |
||
|
Update/Patch Available Apply patches: Microsoft Security Bulletin MS08-059 |
|
|
Vulnerability Details The vulnerability is due to an error in the SNA RPC service that fails to properly authenticate specially crafted RPC requests. A remote attacker can exploit this issue by specially crafting a malicious RPC request and sending it to the target service. Successful exploitation could allow the attacker to execute arbitrary code on an affected system. |
Protection Overview
By enabling this protection, SmartDefense will detect and block remote access to the vulnerable RPC interface.
In order for the protection to be activated, update your VPN-1/InterSpect/Connectra product to the latest SmartDefense update. For information on how to update SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.