Microsoft Windows Locator服务存在远程缓冲区溢出漏洞发布时间:2003-01-22 更新时间:2003-01-30 严重程度:高 威胁程度:远程管理员权限 错误类型:边界检查错误 利用方式:服务器模式 BUGTRAQ ID:6666 CVE(CAN) ID:CAN-2003-0003 受影响系统 Microsoft Windows 2000 Advanced Server SP3详细描述 Microsoft RPC (Remote Procedure Call) Locator服务维护着RPC列表和网络服务的系统,一般默认情况下只有域控制器上运行。 当在网络上搜索RPC服务时,WINDOWS RPC客户端会连接域控制器上的TCP 139/445端口,并通过"locator"有名管道搜索服务/服务器,攻攻击者通过提供包含超长字符串作为搜索条目名,Locator服务在处理的时候就可以导致发生堆栈溢出。主要问题是由于不安全的调用wcscpy()。 测试代码 尚无 解决方案 使用如下命令关闭"Locator"服务: sc stop RpcLocator 补丁下载: Microsoft Windows 2000 Professional SP3: Microsoft Patch Q810833_W2K_SP4_X86_EN.exe http://microsoft.com/downloads/details.aspx?FamilyId=33FF827A-D5DB-4F92-9DEF-4D91A140E0E0&displaylang=en Microsoft Windows 2000 Server SP3: Microsoft Patch Q810833_W2K_SP4_X86_EN.exe http://microsoft.com/downloads/details.aspx?FamilyId=33FF827A-D5DB-4F92-9DEF-4D91A140E0E0&displaylang=en Microsoft Windows 2000 Advanced Server SP3: Microsoft Patch Q810833_W2K_SP4_X86_EN.exe http://microsoft.com/downloads/details.aspx?FamilyId=33FF827A-D5DB-4F92-9DEF-4D91A140E0E0&displaylang=en Microsoft Windows 2000 Terminal Services SP3: Microsoft Patch Q810833_W2K_SP4_X86_EN.exe http://microsoft.com/downloads/details.aspx?FamilyId=33FF827A-D5DB-4F92-9DEF-4D91A140E0E0&displaylang=en Microsoft Windows 2000 Datacenter Server SP3: Microsoft Patch Q810833_W2K_SP4_X86_EN.exe http://microsoft.com/downloads/details.aspx?FamilyId=33FF827A-D5DB-4F92-9DEF-4D91A140E0E0&displaylang=en Microsoft Windows 2000 Advanced Server SP2: Microsoft Patch Q810833_W2K_SP4_X86_EN.exe http://microsoft.com/downloads/details.aspx?FamilyId=33FF827A-D5DB-4F92-9DEF-4D91A140E0E0&displaylang=en Microsoft Windows 2000 Datacenter Server SP2: Microsoft Patch Q810833_W2K_SP4_X86_EN.exe http://microsoft.com/downloads/details.aspx?FamilyId=33FF827A-D5DB-4F92-9DEF-4D91A140E0E0&displaylang=en Microsoft Windows 2000 Professional SP2: Microsoft Patch Q810833_W2K_SP4_X86_EN.exe http://microsoft.com/downloads/details.aspx?FamilyId=33FF827A-D5DB-4F92-9DEF-4D91A140E0E0&displaylang=en Microsoft Windows 2000 Server SP2: Microsoft Patch Q810833_W2K_SP4_X86_EN.exe http://microsoft.com/downloads/details.aspx?FamilyId=33FF827A-D5DB-4F92-9DEF-4D91A140E0E0&displaylang=en Microsoft Windows 2000 Terminal Services SP2: Microsoft Patch Q810833_W2K_SP4_X86_EN.exe http://microsoft.com/downloads/details.aspx?FamilyId=33FF827A-D5DB-4F92-9DEF-4D91A140E0E0&displaylang=en Microsoft Windows 2000 Terminal Services SP1: Microsoft Windows 2000 Server SP1: Microsoft Windows 2000 Professional SP1: Microsoft Windows 2000 Advanced Server SP1: Microsoft Windows 2000 Datacenter Server SP1: Microsoft Windows XP Home SP1: Microsoft Patch Q810833_WXP_SP2_x86_ENU.exe http://microsoft.com/downloads/details.aspx?FamilyId=DF24197E-6217-4ABD-A244-0A53320B2813&displaylang=en Microsoft Windows XP Professional SP1: Microsoft Patch Q810833_WXP_SP2_x86_ENU.exe http://microsoft.com/downloads/details.aspx?FamilyId=DF24197E-6217-4ABD-A244-0A53320B2813&displaylang=en Microsoft Windows XP 64-bit Edition SP1: Microsoft Patch Q810833_WXP_SP2_ia64_ENU.exe http://microsoft.com/downloads/details.aspx?FamilyId=B8999D16-3DAD-4E20-B46E-E1AEFB1F6673&displaylang=en Microsoft Windows XP 64-bit Edition : Microsoft Patch Q810833_WXP_SP2_ia64_ENU.exe http://microsoft.com/downloads/details.aspx?FamilyId=B8999D16-3DAD-4E20-B46E-E1AEFB1F6673&displaylang=en Microsoft Windows 2000 Server : Microsoft Windows 2000 Advanced Server : Microsoft Windows 2000 Server Japanese Edition : Microsoft Patch Q810833_W2K_SP4_nec98_JA.exe http://microsoft.com/downloads/details.aspx?FamilyId=1B142CF9-CADA-4DFF-B42D-7E2022A17E6A&displaylang=ja Microsoft Windows XP Professional : Microsoft Patch Q810833_WXP_SP2_x86_ENU.exe http://microsoft.com/downloads/details.aspx?FamilyId=DF24197E-6217-4ABD-A244-0A53320B2813&displaylang=en Microsoft Windows XP Home : Microsoft Patch Q810833_WXP_SP2_x86_ENU.exe http://microsoft.com/downloads/details.aspx?FamilyId=DF24197E-6217-4ABD-A244-0A53320B2813&displaylang=en Microsoft Windows 2000 Datacenter Server : Microsoft Windows 2000 Professional : Microsoft Windows 2000 Terminal Services : Microsoft Windows NT Enterprise Server 4.0 SP6a: Microsoft Patch Q810833i.EXE http://microsoft.com/downloads/details.aspx?FamilyId=F92D1E86-590A-4DA5-93F2-FCC6300A1A43&displaylang=en Microsoft Patch JPNQ810833n.EXE http://microsoft.com/downloads/details.aspx?FamilyId=F211C932-D442-4A1A-B385-77975DE3B280&displaylang=ja Windows NT Japanese Version Microsoft Patch CHPQ810833i.EXE http://microsoft.com/downloads/details.aspx?FamilyId=C8AAB17B-48B2-4E9F-B06F-2A54BA59A45F&displaylang=zh-tw Windows NT Chinese - Hong Kong Version Microsoft Windows NT Server 4.0 SP6a: Microsoft Patch Q810833i.EXE http://microsoft.com/downloads/details.aspx?FamilyId=F92D1E86-590A-4DA5-93F2-FCC6300A1A43&displaylang=en Microsoft Patch JPNQ810833n.EXE http://microsoft.com/downloads/details.aspx?FamilyId=F211C932-D442-4A1A-B385-77975DE3B280&displaylang=ja Windows NT Japanese Version Microsoft Patch CHPQ810833i.EXE http://microsoft.com/downloads/details.aspx?FamilyId=C8AAB17B-48B2-4E9F-B06F-2A54BA59A45F&displaylang=zh-tw Windows NT Chinese - Hong Kong Version Microsoft Windows NT Terminal Server 4.0 SP6a: Microsoft Windows NT Workstation 4.0 SP6a: Microsoft Patch Q810833i.EXE http://microsoft.com/downloads/details.aspx?FamilyId=F92D1E86-590A-4DA5-93F2-FCC6300A1A43&displaylang=en Microsoft Patch JPNQ810833n.EXE http://microsoft.com/downloads/details.aspx?FamilyId=F211C932-D442-4A1A-B385-77975DE3B280&displaylang=ja Windows NT Japanese Version Microsoft Patch CHPQ810833i.EXE http://microsoft.com/downloads/details.aspx?FamilyId=C8AAB17B-48B2-4E9F-B06F-2A54BA59A45F&displaylang=zh-tw Windows NT Chinese - Hong Kong Version Microsoft Windows NT Workstation 4.0 SP6: Microsoft Windows NT Server 4.0 SP6: Microsoft Windows NT Terminal Server 4.0 SP6: Microsoft Patch Q810833i.EXE http://microsoft.com/downloads/details.aspx?FamilyId=EB651162-97F2-47F9-8E99-016B35B7646D&displaylang=en 相关信息 David Litchfield of Next Generation Security Software Ltd. 参考:http://online.securityfocus.com/archive/1/309321 http://www.microsoft.com/security/security_bulletins/ms03-001.asp |