Microsoft Windows SMB Server service information disclosure
| win-smb-information-disclosure (26820) |
Description:
Multiple could allow a remote attacker to obtain sensitive information, caused by an unchecked buffer in the Server Message Block (SMB) protocol driver. A remote attacker could exploit this vulnerability by sending a specially-crafted message to an affected system which would allow the attacker to read information stored in SMB buffers.
Note: This vulnerability is in Microsoft's implementation of SMB, not in the protocol itself.
Platforms Affected:
- Microsoft, Windows 2000 SP4
- Microsoft, Windows 2003
- Microsoft, Windows 2003 Server x64
- Microsoft, Windows 2003 Server Itanium
- Microsoft, Windows 2003 Server SP1 Itanium
- Microsoft, Windows 2003 Server SP1
- Microsoft, Windows XP Professional x64
- Microsoft, Windows XP SP1
- Microsoft, Windows XP SP2
Remedy:
Apply the appropriate patch for your system, as listed in the latest Microsoft Security Bulletin. See References.
— OR —
Use Microsoft Automatic Update if it is supported by your operating system. The original bulletin issued by Microsoft has been superceded.
Consequences:
Obtain Information
References:
- Full-Disclosure Mailing List, Tue Jul 11 2006 - 17:23:39 CDT, Microsoft SMB Information Disclosure Vulnerability CVE-2006-1315 at http://archives.neohapsis.com/archives/fulldisclosure/2006-07/0231.html.
- Full-Disclosure Mailing List, Wed Jul 12 2006 - 07:53:56 CDT, Repost of Microsoft SMB Information Disclosure Vulnerability CVE-2006-1315 at http://archives.neohapsis.com/archives/fulldisclosure/2006-07/0243.html.
- Microsoft Security Bulletin MS06-035, Vulnerability in Server Service Could Allow Remote Code Execution (917159) at http://www.microsoft.com/technet/security/Bulletin/MS06-035.mspx.
- Microsoft Security Bulletin MS06-063, Vulnerability in Server Service Could Allow Denial of Service and Remote Code Execution (923414) at http://www.microsoft.com/technet/security/bulletin/ms06-063.mspx.
- Microsoft Security Bulletin MS08-063, Vulnerability in SMB Could Allow Remote Code Execution (957095) at http://www.microsoft.com/technet/security/Bulletin/MS08-063.mspx.
- ASA-2006-135: Windows Security Updates for July 2006 - (MS06-033 - MS06-039)
- BID-18891: Microsoft Windows Server Driver Remote Information Disclosure Vulnerability
- CVE-2006-1315: The Server Service (SRV.SYS driver) in Microsoft Windows 2000 SP4, XP SP1 and SP2, Server 2003 up to SP1, and other products, allows remote attackers to obtain sensitive information via crafted requests that leak information in SMB buffers, which are not properly initialized, aka SMB Information Disclosure Vulnerability.
- OSVDB ID: 27155: Microsoft Windows Server Service SRV.SYS Crafted Request SMB Information Disclosure
- SA21007: Microsoft Windows Server Service Two Vulnerabilities
- SECTRACK ID: 1016467: Windows Server Service Buffer Overflows Let Remote Users View SMB Information and Execute Arbitrary Code
- US-CERT VU#333636: Microsoft Server Service may disclose information used to store SMB traffic
- VUPEN/ADV-2006-2753: Microsoft Windows Heap Overflow and Information Disclosure Vulnerabilities (MS06-035)
Reported:
Jul 11, 2006
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2009 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
