Microsoft Malware Protection Engine file denial of service
| malwareprotectionengine-file-dos (42107) |
Description:
Microsoft Malware Protection Engine is vulnerable to a denial of service, caused by improper validation of input when parsing files. By persuading a victim to scan a specially-crafted file using the Microsoft Malware Protection Engine, a remote attacker could cause the Malware Protection Engine to become unresponsive and eventually restart. An attacker could exploit this vulnerability by hosting the malicious file on a Web site or sending the file as an email attachment.
Platforms Affected:
- Microsoft, Antigen for Exchange
- Microsoft, Antigen for SMTP Gateway
- Microsoft, Forefront Client Security
- Microsoft, Forefront Security for Exchange Server
- Microsoft, Forefront Security for SharePoint
- Microsoft, Standalone System Sweeper located in Diagnostics and Recovery Toolset 6.0
- Microsoft, Windows Defender
- Microsoft, Windows Live OneCare
Remedy:
Apply the appropriate patch for your system, as listed in Microsoft Security Bulletin MS08-029. See References.
Consequences:
Denial of Service
References:
- HPSBST02336 SSRT080071 rev.1, Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-026 to MS08-029 at http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?lang=en&cc=us&objectID=c01460710.
- Microsoft Security Bulletin MS08-029, Vulnerabilities in Microsoft Malware Protection Engine Could Allow Denial of Service (952044) at http://www.microsoft.com/technet/security/bulletin/ms08-029.mspx.
- ASA-2008-210: MS08-029 Vulnerabilities in Microsoft Malware Protection Engine Could Allow Denial of Service (952044)
- BID-29060: Microsoft Malware Protection Engine File Processing Remote Denial Of Service Vulnerability
- CVE-2008-1437: Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (engine hang and restart) via a crafted file, a different vulnerability than CVE-2008-1438.
- FrSIRT/ADV-2008-1506: Microsoft Malware Protection Engine Remote DoS Vulnerability (MS08-029)
- SA30172: Microsoft Malware Protection Engine File Parsing Denial of Service
- SECTRACK ID: 1020016: Microsoft Malware Protection Engine Lets Remote Users Deny Service
Reported:
May 13, 2008
The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.
Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.
For corrections or additions please email xforce@iss.net
