40069 : Microsoft Windows TCP/IP ICMP RDP Packet Handling Remote DoS
Printer | http://osvdb.org/40069 | Email This | Edit Vulnerability

Views This Week

4

Views All Time

1125

Info

Last Modified

6 months ago

Percent Complete

90%

Disclosure

Jan 08, 2008

Discovery

Unknown

Dates

Exploit

Unknown

Solution

Jan 08, 2008

Description

Windows contains a flaw that may allow a remote denial of service. The issue is triggered when handling fragmented router advertisement ICMP queries, and will result in loss of availability for the platform.

Classification

Location: Remote/Network Access Required
Attack Type: Denial of Service, Input Manipulation
Impact: Loss of Availability
Solution: Patch
Exploit: Exploit Unknown
Disclosure: Vendor Verified

Technical

Successful exploitation requires that Router Discovery Protocol (RDP) is enabled (disabled by default).

Solution

Currently, there are no known workarounds or upgrades to correct this issue. However, Microsoft has released a patch to address this vulnerability.

Products

Microsoft Corporation
Watch-list
Windows
Watch-list
XP SP2
XP Pro x64 Edition SP2
2000 SP4
XP Pro x64 Edition
Windows Server
Watch-list
2003 SP1
2003 x64 Edition
2003 for Itanium SP1
2003 SP2
2003 x64 Edition SP2
2003 for Itanium SP2
Small Business Server
Watch-list
2003 SP1
2003 R2
2003 R2 SP2
Home Server
Watch-list
Unspecified or Unknown

References

Tools & Filters

Nessus

29893

Credit

Unknown or Incomplete

Blogs

2008/02/08 15:41:20 | MS08-001

from: mcwresearch.com

MS08-001 Am I being Chicken Little in thinking that remote kernel attacks such as one leveraging the MS08-001 vulnerability will be the next ... radar (FUD-ar?) and it isn’t picking up anything on recent chatter on MS08-001. So far I’m hearing

2008/02/08 11:13:20 | Security Vulnerability Research & Defence blog - worth a read for sure - eg MS08-001 - The case of the Moderate, Important, and Critical network vulnerabilities

from: David Overton's Blog

My background covers security and I've started reading this blog (Security Vulnerability Research & Defense) ... issue in more detail. CVE-2007-0066 describes a vulnerability in parsing ICMP router advertisement

2008/02/02 11:44:03 | Microsoft Windows Server 2003 may have ‘critical’ flaw

from: Blog.KtecTraining.com

Microsoft Windows Server 2003 may have ‘critical’ flaw February 2nd, ... (SBS) 2003. The security bulletin MS08-001 is available on the Microsoft web site

2008/02/01 07:19:43 | MS08-001 Proof-Of-Concept Exploit

from: #define _MY_CORE_DUMP_

Check out this cool proof-of-concept exploit developed by immunitysec for the IGMPv3 vulnerability (MS08-001). http://immunityinc.com/documentation/ms08_001.html The tool being used

2008/01/31 17:54:51 | Exploit for MS08-001 Demonstrated - Security Watch

from: The Steve Zone

  When Microsoft released the MS08-001 security bulletin earlier this year they were careful to note mitigating factors that made it difficult to exploit. "Attacks attempting to exploit this vulnerability would most likely result in a denial of service condition. However remote code execution could be possible." Exploit for MS08-001

2008/01/31 16:28:07 | Microsoft's IGMPv3 Vulnerability Can Be Exploited

from: [H]ard|OCP - hardocp.com

Microsoft's IGMPv3 Vulnerability Can Be Exploited What is the best way to find out whether or not a vulnerability can be exploited? ... that the MS08-001 IGMPv3 vulnerability is highly exploitable," said Dave Aitel, CTO of Immunity, in a message

2008/01/31 15:55:18 | Exploit for MS08-001 Demonstrated

from: PC Magazine Security Watch - Tech Security News, Reviews, Patches and Advice

A research outfit confirms fears that a network worm is possible using a recent Windows bug.

2008/01/30 17:31:28 | New attack proves critical Windows bug 'highly exploitable'

from: Windows Updated

Security researchers Tuesday said they'd discredited Microsoft's claim that the year's first critical Windows vulnerability would be " ... exploit for the TCP/IP flaw spelled out Jan. 8 in Microsoft's MS08-001 security bulletin, and posted ... of code first issued two weeks ago. "This demonstrates conclusively that the MS08-001 IGMPv3

2008/01/30 17:15:24 | New Windows TCP/IP Vulnerability (MS08-001)

from: spylogic.net - What secret is your computer hiding?

Lots of talk on the net recently about the first "critical" vulnerability (MS08-001) released by Microsoft this year. If exploited, this vulnerability can allow an attacker to run arbitrary code

2008/01/30 17:05:00 | New attack proves critical Windows bug ‘highly exploitable’

from: Technomania

Security researchers Tuesday said they'd discredited Microsoft's claim that the year's first critical Windows vulnerability would be " ... for the TCP/IP flaw spelled out Jan. 8 in Microsoft's MS08-001 security bulletin, and posted ... of code first issued two weeks ago."This demonstrates conclusively that the MS08-001 IGMPv3

2008/01/30 16:51:16 | New attack proves critical Windows bug 'highly exploitable'

from: WinBeta.org Beta News and Reviews

Security researchers yesterday said they'd discredited Microsoft's claim that the year's first critical Windows vulnerability would be " ... exploit for the TCP/IP flaw spelled out Jan. 8 in Microsoft's MS08-001 security bulletin ... version of code first issued two weeks ago. "This demonstrates conclusively that the MS08-001 IGMPv3

2008/01/30 14:00:17 | Attack Proves Critical Windows Bug ‘Highly Exploitable’

from: Liquidmatrix Security Digest

Aitel to Microsoft…Ya know what? Uh, uh. From Computer World: ... s MS08-001 security bulletin, and posted a Flash demonstration of the attack on its Web site ... conclusively that the MS08-001 IGMPv3 vulnerability is highly exploitable,” said Dave Aitel, Immunity’

2008/01/30 17:40:34 | Critical vulnerability for XP and Vista proven “highly exploitable”

from: | IT News Digest | TechRepublic.com

On January 8, Microsoft released security bulletin MS08-001, ... to the public. From ComputerWorld: “This demonstrates conclusively that the MS08-001 IGMPv3

2008/01/29 17:47:16 | Windows Home Server Vulnerable to Critical Bug

from: VIBE — Technology For Life

Windows Home Server Vulnerable to Critical Bug January 29, 2008 – 9:50 am ’ For the second time in three days, Microsoft Corp ... to the vulnerabilities spelled out by the MS08-001 security bulletin, according to a Friday update. The advisory

2008/01/28 05:39:25 | Windows Home Server vulnerable to critical bug, too

from: Donna's SecurityFlash

For the second time in three days, Microsoft Corp. added another product to the list of those vulnerable to a critical bug patched nearly three weeks ago. Windows Home Server, the company's newest operating system, is also at risk to the vulnerabilities spelled out by the MS08-001 security bulletin, according to a Friday update

2008/01/27 17:23:16 | Microsoft Security Bulletin MS08-001 for Windows Home Server

from: Windows News

Microsoft Security Bulletin MS08-001 for Windows Home Server January 27th, 2008 By BSchwarz You may notice an update for your Home Server if it has not been automatically downloaded and installed

2008/01/27 16:16:14 | Microsoft Security Bulletin MS08-001 for Windows Home Server

from: Bob's Tech Blog and Resources

You may notice an update for your Home Server if it has not been automatically downloaded and installed by Microsoft update ... are available in Microsoft Security Bulletin MS08-001. The severity Rating is Critical

2008/01/26 02:02:30 | Microsoft updates Security Bulletin from last Patchday

from: pbnetworks

Microsoft updates Security Bulletin from last Patchday January 25th, 2008 Microsoft has updated its Security Bulletin MS08-001 on the security vulnerabilities in the TCP/IP stack in Windows. The revised bulletin states that Windows Small Business Server 2003

2008/01/25 15:04:00 | Critical flaw threatens Windows Small Business Server

from: Bob's Tech Blog and Resources

Microsoft has warned that another one of its operating system products is vulnerable to a critical vulnerability, that was patched in some operating systems two weeks ago. In an update to its MS08-001 security bulletin, Microsoft said that the latest release of Windows Small Business Server was also critically

2008/01/25 09:38:17 | Windows Small Business Server at risk from critical flaw

from: http://www.dralnux.com

Microsoft said Wednesday that another one of its operating system products is vulnerable to a critical vulnerability, first patched two weeks ago. In an update to its MS08-001 security bulletin, Microsoft said that the latest release of Windows Small Business Server was also critically at risk from a bug in Windows’ networking software

2008/01/07 14:46:11 | ms08 001

from: irdieszm

[ ms08 001] Amazon. Dragonsoft secure scanner vulnerability assessment system security manager ... inclusion vulnerability. Replaces ms06-032: tcp/ip stack cve-2007-0066 dragonsoft vulnerability

Comments

No Comments.

DONATE NOW!

User Status

Quick Searches

Advertisements

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2008 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use