40070 : Microsoft Windows TCP/IP IGMPv3 / MLDv2 Packet Handling Remote Code Execution
Printer | http://osvdb.org/40070 | Email This | Edit Vulnerability

Views This Week

7

Views All Time

1644

Info

Last Modified

5 days ago

Percent Complete

100%

Disclosure

Jan 08, 2008

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Jan 08, 2008

Description

A buffer overflow exists in Windows. The TCP/IP implementation fails to validate IGMPv3 and MLDv2 packets resulting in a buffer overflow. With a specially crafted packet, a remote attacker can cause arbtrary code execution resulting in a loss of integrity.

Classification

Location: Remote/Network Access Required
Attack Type: Input Manipulation
Impact: Loss of Integrity
Solution: Patch
Exploit: Exploit Unavailable
Disclosure: Vendor Verified, Third Party Verified

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability.

Products

Microsoft Corporation
Watch-list
Windows
Watch-list
XP SP2
XP Pro x64 Edition
XP Pro x64 Edition SP2
Vista
Vista x64 Edition
Windows Server
Watch-list
2003 SP1
2003 x64 Edition
2003 for Itanium SP1
2003 SP2
2003 x64 Edition SP2
2003 for Itanium SP2

References

Tools & Filters

Nessus

29893

Credit

  • Alex Wheeler - IBM ISS X-Force
  • Ryan Smith - IBM ISS X-Force

Blogs

2008/02/14 21:16:15 | The first vulnerability in Vista in the new year: hurry up with installing the patch!

from: Computer software news

The first vulnerability in Vista in the new year: hurry up with installing the patch! ... in the bulletin MS08-001. The exploit was based on a malicious code published a few weeks ago and was designed

2008/02/13 17:22:07 | Security UPDATE Alert: 11 Microsoft Security Bulletins for February 2008

from: WINDOWS CENTER

SECURITY UPDATE A Penton Media Property February 13, 2008 If you want to view this on the web go to: http://ct.email.windowsitpro.com/rd/cts?d=33-2373-803-202-62923-183592-0-0-0-1-2-207 ---------------------------------------- ADVERTISEMENT Sophos Instant Messaging, VoIP, P2P,

2008/02/12 21:54:05 | XP SP II Vulnerability

from: tech & co

Demonstration of a XP SP II Exploit WINDOWS ... XP SP II The above URL is a flash movie showing the latest version of the MS08-001 exploit now in CANVAS Early Updates. This demonstrates conclusively that the MS08-001 IGMPv3 vulnerability is highly exploitable. In the movie you can see the attack target a local subnet which is populated

2008/02/12 19:40:35 | February Black Tuesday Overview - UPDATED - SANS Internet Storm Center

from: Chris Mosby at myITforum.com

February Black Tuesday Overview - UPDATED - SANS Internet Storm Center February Black Tuesday Overview Published: 2008-02-12, Last Updated: ... MS08-001. TCP/IP Stack CVE-2008-0084 KB 946456 No publicly known exploits Important Important Less

2008/02/12 14:56:29 | SPAMfighter News - 7 new articles

from: Anti-Spam

[ Your email updates, powered by FeedBlitz] Here are the latest updates for raplist.antispamsite@blogger.com "SPAMfighter News" - 7 new articles Three Found Guilty for SpammingSmall Antivirus Companies Snowed Down by Malware AttacksMalware Enters School Computer NetworkNew Code Demonstrates Exploitation of Critical Windows FlawMortgage

2008/02/03 22:40:11 | The Week in Review - Sunday’s Summary

from: MS Windows Home Server

What was going on this week at mswhs.com? Here’s catch-up time if you missed something! ... ? We bought to your attention the other day that the vulnerabilities detailed in the MS08-001 security

2008/01/31 00:12:46 | F-Secure: PHP IRC Bot "We saw a PHP script that was heavily obfuscated and the configuratio...

from: Rootsecure.net

# Computer World: Mozilla ups Firefox bug threat, slates fix for Feb ... . 8 in Microsoft's MS08-001 security bulletin, and posted a Flash demonstration of the attack" Posted: 30 Jan

2008/02/01 16:10:19 | Server 2003 May Have Critical Flaw

from: Bob's Tech Blog and Resources

In a change from its earlier statements, Microsoft now reports that some versions of Windows Server 2003 have a security flaw rated “critical” rather than merely “important.” If you didn’t install security bulletin MS08-001 after ... , which would have installed MS08-001 if authorized to auto-update. Full story

2008/01/30 23:14:57 | Immunity launched effective exploit for Windows

from: OverFl0w IRC Networks

A workable exploit attack for a TCP/IP vulnerability in Microsoft’s Windows has been launched into the wild courtesy of security firm Immunity. On Jan. 17, it became clear that you shouldn’t dawdle on deploying Microsoft’s MS08-001 patch. That patch, issued Jan. 8, fixed a Transmission Control Protocol/Internet Protocol (TCP/IP

2008/01/30 23:03:37 | New Attack Proves Critical Windows Bug ‘Highly Exploitable’

from: ARP-Cache

New Attack Proves Critical Windows Bug ‘Highly Exploitable’ Category: ... . 8 in Microsoft’s MS08-001 security bulletin, and posted a Flash demonstration of the attack on its Web site ... This demonstrates conclusively that the MS08-001 IGMPv3 vulnerability is highly exploitable,” said Dave Aitel

2008/01/30 22:31:45 | Researchers Fault Microsoft on Windows Vulnerability

from: GigaLaw.com Daily News

Security researchers said they'd discredited Microsoft's claim that the year's first critical Windows vulnerability would be "difficult and unlikely" to be exploited by attackers. Immunity updated a working exploit for the TCP/IP flaw spelled out Jan. 8 in Microsoft's MS08-001 security bulletin, and posted a Flash demonstration of the attack

2008/01/31 03:50:03 | IGMPv3 Vulnerability

from: - Technibble - A Resource for Computer Repair Technicians & to get PC tech support help.

Over three weeks ago, Microsoft released a bulletin with a code MS08-001 and it ranked an IGMP flaw as “Critical” for Windows Vista, Windows Small Business Server, Windows Home Server, and Windows

2008/01/31 02:40:08 | New attack proves critical Windows bug ‘highly exploitable’ (MS08-001 PoC)

from: byteninja.net

New attack proves critical Windows bug ‘highly exploitable’ (MS08-001 PoC) January 31st, 2008 January 30, 2008 (Computerworld) ... s MS08-001 security bulletin, and posted a Flash demonstration of the attack on its Web site

2008/01/30 08:09:58 | Immunity launches exploit for ‘unlikely’ Windows worm hole

from: Hack In The Box :: Keeping Knowledge Free

A workable exploit attack for a TCP/IP vulnerability in Microsoft’s Windows has been launched into the wild courtesy of security firm Immunity. On Jan. 17, it became clear that you shouldn’t dawdle on deploying Microsoft’s MS08-001 patch. That patch, issued Jan. 8, fixed a Transmission Control Protocol/Internet Protocol (TCP/IP) processing

2008/01/30 01:20:03 | Immunity launches exploit for ‘unlikely’ Windows worm hole

from: New Digital Computer —

Immunity launches exploit for ‘unlikely’ Windows worm hole in: ... that you shouldn't dawdle on deploying Microsoft's MS08-001 patch. That patch, issued Jan. 8, fixed

2008/01/29 20:30:12 | Exploit Released for 'Unexploitable' Windows Worm Hole

from: Ryan Naraine's Security Watch

Exploit Released for 'Unexploitable' Windows Worm Hole Remember that MS08-001 worm hole that Microsoft claimed was unexploitable? Well, a private pen-testing and vulnerability research outfit

2008/01/29 17:52:10 | VU#115083:Microsoft Windows IGMPv3 and MLDv2 processing vulnerability

from: US-CERT Vulnerability Notes

Vulnerability Note VU#115083 Microsoft Windows IGMPv3 and MLDv2 processing vulnerability OverviewMicrosoft Windows fails to properly process IGMPv3 ... Security Bulletin MS08-001: A remote code execution vulnerability exists in the Windows kernel due ... . SolutionUpdate Microsoft has released an update to address this issue. See MS08-001 for more

2008/01/29 01:17:00 | Microsoft admits Windows Home Server bug

from: Latest News - PC Advisor

Home OS added to Microsoft's risk list Microsoft has revealed that Windows Home Server, the company's newest operating system, is also at risk to the vulnerabilities spelled out by the MS08-001 security bulletin.

2008/01/26 12:13:22 | Microsoft Security Bulletin MS08-001 – Critical

from: WindowsHomeServer | Serving at home

Microsoft Security Bulletin MS08-001 – Critical January 26, 2008 By: admin Category: ... (CVE-2007-0069), default configurations of Windows Small Business Server 2003 and Windows Home Server

2008/01/26 02:47:00 | Revised MS08-001

from: The Official Blog of the SBS "Diva"

Remember we're critical because we have WINS running ... /IP/IGMPv3 and MLDv2 Vulnerability (CVE-2007-0069) on supported editions of Windows Small Business

2008/01/10 03:36:00 | MS08-001 details

from: Eon Security Blog

A critical vulnerability affecting Windows XP SP2, 2000 SP4, Server 2003 and Vista was patched this tuesday ... . MS08-001 is broken down to CVE-2007-0066 and CVE-2007-0069, the former does not affect Windows Vista

2008/01/08 20:38:05 | Microsoft Tuesday for 1/8/08

from: Random Thoughts from Joel's World

Today MSFT put out their MSFT Black Tuesday patches for the first time in 2008.  (Duh, it's the first time, it's the second week!) ... and MLDv2 Vulnerability - CVE-2007-0069 A remote code execution vulnerability exists in the Windows

2008/01/08 19:38:40 | Microsoft delivers two patches for three vulnerabilities; Plugs Vista hole

from: | Zero Day | ZDNet.com

Microsoft on Tuesday delivered one “critical” addressing two vulnerabilities in XP and Vista and one “important” vulnerability in Windows 2000, XP and Windows Server 2003. The critical patch resolves two vulnerabilities (CVE-2007-0069 and CVE-2007-0066) reported by IBM ISS X-Force. The vulnerability, which involved TCP/IP processing

2008/01/09 20:39:59 | Microsoft rulez, after all (MS08-001)

from: kill-9.it

More than two years ago, I was writing the first No Fills TCP RFC draft ... administrators can opt for either IGMPv3 or MLDv2 (aka CVE-2007-0069). Fun does not stop here

Comments

No Comments.

DONATE NOW!

User Status

Quick Searches

Advertisements

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2008 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use