xfocus logo xfocus title
首页 焦点原创 安全文摘 安全工具 安全漏洞 焦点项目 焦点论坛 关于我们
English Version

Microsoft Windows Locator服务存在远程缓冲区溢出漏洞


发布时间:2003-01-22
更新时间:2003-01-30
严重程度:
威胁程度:远程管理员权限
错误类型:边界检查错误
利用方式:服务器模式

BUGTRAQ ID:6666
CVE(CAN) ID:CAN-2003-0003

受影响系统
Microsoft Windows 2000 Advanced Server SP3
Microsoft Windows 2000 Advanced Server SP2
Microsoft Windows 2000 Advanced Server SP1
Microsoft Windows 2000 Advanced Server
Microsoft Windows 2000 Datacenter Server SP3
Microsoft Windows 2000 Datacenter Server SP2
Microsoft Windows 2000 Datacenter Server SP1
Microsoft Windows 2000 Datacenter Server
Microsoft Windows 2000 Professional SP3
Microsoft Windows 2000 Professional SP2
Microsoft Windows 2000 Professional SP1
Microsoft Windows 2000 Professional
Microsoft Windows 2000 Server SP3
Microsoft Windows 2000 Server SP2
Microsoft Windows 2000 Server SP1
Microsoft Windows 2000 Server
Microsoft Windows 2000 Server Japanese Edition
Microsoft Windows 2000 Terminal Services SP3
Microsoft Windows 2000 Terminal Services SP2
Microsoft Windows 2000 Terminal Services SP1
Microsoft Windows 2000 Terminal Services
Microsoft Windows NT Enterprise Server 4.0 SP6a
Microsoft Windows NT Enterprise Server 4.0 SP6
Microsoft Windows NT Enterprise Server 4.0 SP5
Microsoft Windows NT Enterprise Server 4.0 SP4
Microsoft Windows NT Enterprise Server 4.0 SP3
Microsoft Windows NT Enterprise Server 4.0 SP2
Microsoft Windows NT Enterprise Server 4.0 SP1
Microsoft Windows NT Enterprise Server 4.0
Microsoft Windows NT Server 4.0 SP6a
Microsoft Windows NT Server 4.0 SP6
Microsoft Windows NT Server 4.0 SP5
Microsoft Windows NT Server 4.0 SP4
Microsoft Windows NT Server 4.0 SP3
Microsoft Windows NT Server 4.0 SP2
Microsoft Windows NT Server 4.0 SP1
Microsoft Windows NT Server 4.0
Microsoft Windows NT Terminal Server 4.0 SP6a
Microsoft Windows NT Terminal Server 4.0 SP6
Microsoft Windows NT Terminal Server 4.0 SP5
Microsoft Windows NT Terminal Server 4.0 SP4
Microsoft Windows NT Terminal Server 4.0 SP3
Microsoft Windows NT Terminal Server 4.0 SP2
Microsoft Windows NT Terminal Server 4.0 SP1
Microsoft Windows NT Terminal Server 4.0
Microsoft Windows NT Workstation 4.0 SP6a
Microsoft Windows NT Workstation 4.0 SP6
Microsoft Windows NT Workstation 4.0 SP5
Microsoft Windows NT Workstation 4.0 SP4
Microsoft Windows NT Workstation 4.0 SP3
Microsoft Windows NT Workstation 4.0 SP2
Microsoft Windows NT Workstation 4.0 SP1
Microsoft Windows NT Workstation 4.0
Microsoft Windows XP 64-bit Edition SP1
Microsoft Windows XP 64-bit Edition
Microsoft Windows XP Home SP1
Microsoft Windows XP Home
Microsoft Windows XP Professional SP1
Microsoft Windows XP Professional
详细描述
Microsoft RPC (Remote Procedure Call) Locator服务维护着RPC列表和网络服务的系统,一般默认情况下只有域控制器上运行。

当在网络上搜索RPC服务时,WINDOWS RPC客户端会连接域控制器上的TCP 139/445端口,并通过"locator"有名管道搜索服务/服务器,攻攻击者通过提供包含超长字符串作为搜索条目名,Locator服务在处理的时候就可以导致发生堆栈溢出。主要问题是由于不安全的调用wcscpy()。

测试代码
尚无

解决方案
使用如下命令关闭"Locator"服务:

sc stop RpcLocator

补丁下载:

Microsoft Windows 2000 Professional SP3:

Microsoft Patch Q810833_W2K_SP4_X86_EN.exe
http://microsoft.com/downloads/details.aspx?FamilyId=33FF827A-D5DB-4F92-9DEF-4D91A140E0E0&displaylang=en

Microsoft Windows 2000 Server SP3:

Microsoft Patch Q810833_W2K_SP4_X86_EN.exe
http://microsoft.com/downloads/details.aspx?FamilyId=33FF827A-D5DB-4F92-9DEF-4D91A140E0E0&displaylang=en

Microsoft Windows 2000 Advanced Server SP3:

Microsoft Patch Q810833_W2K_SP4_X86_EN.exe
http://microsoft.com/downloads/details.aspx?FamilyId=33FF827A-D5DB-4F92-9DEF-4D91A140E0E0&displaylang=en

Microsoft Windows 2000 Terminal Services SP3:

Microsoft Patch Q810833_W2K_SP4_X86_EN.exe
http://microsoft.com/downloads/details.aspx?FamilyId=33FF827A-D5DB-4F92-9DEF-4D91A140E0E0&displaylang=en

Microsoft Windows 2000 Datacenter Server SP3:

Microsoft Patch Q810833_W2K_SP4_X86_EN.exe
http://microsoft.com/downloads/details.aspx?FamilyId=33FF827A-D5DB-4F92-9DEF-4D91A140E0E0&displaylang=en

Microsoft Windows 2000 Advanced Server SP2:

Microsoft Patch Q810833_W2K_SP4_X86_EN.exe
http://microsoft.com/downloads/details.aspx?FamilyId=33FF827A-D5DB-4F92-9DEF-4D91A140E0E0&displaylang=en

Microsoft Windows 2000 Datacenter Server SP2:

Microsoft Patch Q810833_W2K_SP4_X86_EN.exe
http://microsoft.com/downloads/details.aspx?FamilyId=33FF827A-D5DB-4F92-9DEF-4D91A140E0E0&displaylang=en

Microsoft Windows 2000 Professional SP2:

Microsoft Patch Q810833_W2K_SP4_X86_EN.exe
http://microsoft.com/downloads/details.aspx?FamilyId=33FF827A-D5DB-4F92-9DEF-4D91A140E0E0&displaylang=en

Microsoft Windows 2000 Server SP2:

Microsoft Patch Q810833_W2K_SP4_X86_EN.exe
http://microsoft.com/downloads/details.aspx?FamilyId=33FF827A-D5DB-4F92-9DEF-4D91A140E0E0&displaylang=en

Microsoft Windows 2000 Terminal Services SP2:

Microsoft Patch Q810833_W2K_SP4_X86_EN.exe
http://microsoft.com/downloads/details.aspx?FamilyId=33FF827A-D5DB-4F92-9DEF-4D91A140E0E0&displaylang=en

Microsoft Windows 2000 Terminal Services SP1:
Microsoft Windows 2000 Server SP1:
Microsoft Windows 2000 Professional SP1:
Microsoft Windows 2000 Advanced Server SP1:
Microsoft Windows 2000 Datacenter Server SP1:
Microsoft Windows XP Home SP1:

Microsoft Patch Q810833_WXP_SP2_x86_ENU.exe
http://microsoft.com/downloads/details.aspx?FamilyId=DF24197E-6217-4ABD-A244-0A53320B2813&displaylang=en

Microsoft Windows XP Professional SP1:

Microsoft Patch Q810833_WXP_SP2_x86_ENU.exe
http://microsoft.com/downloads/details.aspx?FamilyId=DF24197E-6217-4ABD-A244-0A53320B2813&displaylang=en

Microsoft Windows XP 64-bit Edition SP1:

Microsoft Patch Q810833_WXP_SP2_ia64_ENU.exe
http://microsoft.com/downloads/details.aspx?FamilyId=B8999D16-3DAD-4E20-B46E-E1AEFB1F6673&displaylang=en

Microsoft Windows XP 64-bit Edition :

Microsoft Patch Q810833_WXP_SP2_ia64_ENU.exe
http://microsoft.com/downloads/details.aspx?FamilyId=B8999D16-3DAD-4E20-B46E-E1AEFB1F6673&displaylang=en

Microsoft Windows 2000 Server :
Microsoft Windows 2000 Advanced Server :
Microsoft Windows 2000 Server Japanese Edition :

Microsoft Patch Q810833_W2K_SP4_nec98_JA.exe
http://microsoft.com/downloads/details.aspx?FamilyId=1B142CF9-CADA-4DFF-B42D-7E2022A17E6A&displaylang=ja

Microsoft Windows XP Professional :

Microsoft Patch Q810833_WXP_SP2_x86_ENU.exe
http://microsoft.com/downloads/details.aspx?FamilyId=DF24197E-6217-4ABD-A244-0A53320B2813&displaylang=en

Microsoft Windows XP Home :

Microsoft Patch Q810833_WXP_SP2_x86_ENU.exe
http://microsoft.com/downloads/details.aspx?FamilyId=DF24197E-6217-4ABD-A244-0A53320B2813&displaylang=en

Microsoft Windows 2000 Datacenter Server :
Microsoft Windows 2000 Professional :
Microsoft Windows 2000 Terminal Services :
Microsoft Windows NT Enterprise Server 4.0 SP6a:

Microsoft Patch Q810833i.EXE
http://microsoft.com/downloads/details.aspx?FamilyId=F92D1E86-590A-4DA5-93F2-FCC6300A1A43&displaylang=en

Microsoft Patch JPNQ810833n.EXE
http://microsoft.com/downloads/details.aspx?FamilyId=F211C932-D442-4A1A-B385-77975DE3B280&displaylang=ja
Windows NT Japanese Version

Microsoft Patch CHPQ810833i.EXE
http://microsoft.com/downloads/details.aspx?FamilyId=C8AAB17B-48B2-4E9F-B06F-2A54BA59A45F&displaylang=zh-tw
Windows NT Chinese - Hong Kong Version

Microsoft Windows NT Server 4.0 SP6a:

Microsoft Patch Q810833i.EXE
http://microsoft.com/downloads/details.aspx?FamilyId=F92D1E86-590A-4DA5-93F2-FCC6300A1A43&displaylang=en

Microsoft Patch JPNQ810833n.EXE
http://microsoft.com/downloads/details.aspx?FamilyId=F211C932-D442-4A1A-B385-77975DE3B280&displaylang=ja
Windows NT Japanese Version

Microsoft Patch CHPQ810833i.EXE
http://microsoft.com/downloads/details.aspx?FamilyId=C8AAB17B-48B2-4E9F-B06F-2A54BA59A45F&displaylang=zh-tw
Windows NT Chinese - Hong Kong Version

Microsoft Windows NT Terminal Server 4.0 SP6a:
Microsoft Windows NT Workstation 4.0 SP6a:

Microsoft Patch Q810833i.EXE
http://microsoft.com/downloads/details.aspx?FamilyId=F92D1E86-590A-4DA5-93F2-FCC6300A1A43&displaylang=en

Microsoft Patch JPNQ810833n.EXE
http://microsoft.com/downloads/details.aspx?FamilyId=F211C932-D442-4A1A-B385-77975DE3B280&displaylang=ja
Windows NT Japanese Version

Microsoft Patch CHPQ810833i.EXE
http://microsoft.com/downloads/details.aspx?FamilyId=C8AAB17B-48B2-4E9F-B06F-2A54BA59A45F&displaylang=zh-tw
Windows NT Chinese - Hong Kong Version

Microsoft Windows NT Workstation 4.0 SP6:
Microsoft Windows NT Server 4.0 SP6:
Microsoft Windows NT Terminal Server 4.0 SP6:

Microsoft Patch Q810833i.EXE
http://microsoft.com/downloads/details.aspx?FamilyId=EB651162-97F2-47F9-8E99-016B35B7646D&displaylang=en

相关信息
David Litchfield of Next Generation Security Software Ltd.
参考:http://online.securityfocus.com/archive/1/309321
http://www.microsoft.com/security/security_bulletins/ms03-001.asp