CERT-In Vulnerability Note
CIVN-2005-0074
Microsoft Print Spooler service buffer overflow vulnerability
Original Issue Date:August 10, 2005
Severity Rating: HIGH
Systems Affected
Microsoft Windows 2000 Service Pack 4 Microsoft Windows XP Service Pack 1 and Service Pack 2 Microsoft Windows Server 2003 Microsoft Windows Server 2003 for Itanium-based Systems
Not Affected Microsoft has mentioned that the following versions are not affected by this vulnerability. - Microsoft Windows XP Professional x64 Edition
- Microsoft Windows Server 2003 Service Pack 1
- Microsoft Windows Server 2003 with SP1 for Itanium-based Systems
- Microsoft Windows Server 2003 x64 Edition
- Microsoft Windows 98
- Microsoft Windows 98 Second Edition SE
- Microsoft Windows Millennium Edition ME
Overview
A vulnerability has been reported in Microsoft Print Spooler service which could be exploited by an attacker to compromise affected systems or cause Denial of Service.
Description
The Microsoft Print Spooler service manages the printing process and related tasks such as retrieving the location of the correct printer driver, loading that driver, spooling high-level function calls into a print job, and scheduling print jobs.
This vulnerability is caused due to an unchecked buffer in the Spoolsv.exe Print Spooler service . An attacker could remotely exploit this vulnerability by sending a specially crafted message to the affected system causing buffer overflow. An attacker could run a specially-crafted application to exploit this vulnerability locally. Successful exploitation would enable the attacker to run arbitrary code or cause Denial of Service.
Workaround
Disable Print Spooler service if printing is not required On Windows 2000 SP 4, remove the Print Spooler service from the NullSessionPipes registry key.
Solution
Apply the appropriate patches as mentioned in Microsoft Security Bulletin
MS05-043
http://www.microsoft.com/technet/security/Bulletin/MS05-043.mspx
Vendor Information
Microsoft Corporation
http://www.microsoft.com/technet/security/Bulletin/MS05-043.mspx
References
Microsoft Security Bulletin MS05-043
http://www.microsoft.com/technet/security/Bulletin/MS05-043.mspx
Secunia Advisory
http://secunia.com/advisories/16356
US-CERT Vulnerability Note VU#220821
http://www.kb.cert.org/vuls/id/220821
CVE Name
CAN-2005-1984
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|