Subscribe to Windows IT Pro
December 01, 2004 12:00 AM

Arbitrary Code Execution in Microsoft WINS

Windows IT Pro
InstantDoc ID #44644
Rating: (0)

Reported November 28, 2004, by Immunity

VERSIONS AFFECTED                                           

·         Microsoft WINS

DESCRIPTION
A vulnerability exists in Microsoft WINS that could result in the remote execution of arbitrary code on the vulnerable system. WINS replication is done on TCP port 42 using a Microsoft proprietary protocol. During this protocol flow, a memory pointer is sent from server to client, and the client uses that pointer to talk with the server. If a specially crafted packet is sent to the server, an attacker can control the pointer and can make it point to an attacker-controlled buffer and eventually write 16 bytes at any location.

VENDOR RESPONSE
Microsoft, has released "How to help protect against a WINS security issue," http://support.microsoft.com/kbid?=890710, to address this vulnerability.

CREDIT
Discovered by Nicolas Waisman.

Related Content:

ARTICLE TOOLS

Comments
  • Anonymous User
    8 years ago
    Dec 02, 2004

    http://support.microsoft.com/search/default.aspx?catalog=LCID%3D1033&query=890710&x=0&y=0

    -kewakl

  • Anonymous User
    8 years ago
    Dec 02, 2004

    Oops- should have been

    http://support.microsoft.com/default.aspx?scid=kb;en-us;890710



    prev link points to the search page.
    -kewakl

  • Anonymous User
    8 years ago
    Dec 02, 2004

    The URL given doesn't work, and MSKB searches on the title given also don't turn anything up. (and it would be nice if it was actually a link)

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.