Update Protection against Multiple Microsoft DNS Server Cache Spoofing Vulnerabilities (MS09-008)
| Check Point Reference: | CPAI-2009-036 | |
| Date Published: | ||
| Severity: | ||
| Source: | Microsoft Security Bulletin MS09-008 | |
| Industry Reference(s): | CVE-2009-0233 CVE-2009-0234 |
|
| Protection Provided by: |
Security Gateway
|
|
| Who is Vulnerable? Microsoft Windows 2000 Server SP4 Windows Server 2003 SP1 Windows Server 2003 SP2 Windows Server 2003 x64 Edition Windows Server 2003 x64 Edition SP2 Windows Server 2003 with SP1 (Itanium) Windows Server 2003 with SP2 (Itanium) Windows Server 2008 for 32-bit Systems Windows Server 2008 for x64-based Systems | ||
| Vulnerability Description Multiple spoofing vulnerabilities have been reported in Windows DNS server. These vulnerabilities could allow a remote attacker to spoof responses and insert records into the DNS server's cache. The DNS caching resolver service saves the responses to DNS queries so that the DNS server is not repeatedly queried for the same information. A remote attacker may exploit these issues to create DNS cache poisoning. |
||
|
Update/Patch Available Apply patches: Microsoft Security Bulletin MS09-008 |
|
|
Vulnerability Details The vulnerabilities are due to an error in the Windows DNS server that fails to re-use cached responses when receiving specifically crafted duplicate queries, thereby reducing entropy and allowing greater predictability of subsequent transaction IDs used by the DNS server. A remote attacker may exploit this issue by sending specific queries to a vulnerable DNS server and at the same time respond back in a manner that allows the attacker to insert false or misleading DNS data. By poisoning a DNS server, a remote attacker could direct users to malicious sites or prevent them from accessing web sites of their choice. |
Protection Overview
By enabling this protection, SmartDefense will detect and block multiple requests with the same domain name sent to the vulnerable server.
In order for the protection to be activated, update your Security Gateway/VPN-1/InterSpect product to the latest SmartDefense update. For information on how to update SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.
To configure the defense, select your product from the list below and follow the related protection steps.
Additional Information
For more information on DNS cache poisoning see SBP-2007-08.