| CERT-In Vulnerability Note 
                                                                      CIVN-2007-0142 Remote Code Execution Vulnerability in Microsoft DNS Server
 Original Issue Date:November  14, 2007
 Severity Rating: MEDIUM
 Systems Affected  
  Microsoft Windows 2000 Server Service Pack 4
  Microsoft Windows Server 2003 Service Pack 1
  Microsoft Windows Server 2003 Service Pack 2
  Microsoft Windows Server 2003 x64 Edition
  Microsoft Windows Server 2003 x64 Edition Service Pack 2
  Microsoft Windows Server 2003 SP1  Itanium 
  Microsoft Windows Server 2003 SP2  Itanium   Overview A vulnerability have been reported in Microsoft DNS server that could be exploited by an attacker to poison the DNS Server cache .The vulnerability could allow unauthenticated attacker to cause a window DNS server to provide incorrect response to DNS queries. DescriptionA spoofing vulnerability exists in Microsoft DNS server service  dns.exe  while sending out queries to upstream DNS server .. 
 This vulnerability could allow an attacker to poison the DNS cache via a specially crafted DNS response with a guessed transaction value. An attacker who successfully exploited this vulnerability could respond to a DNS query with false or misleading information, thereby redirecting network traffic from legitimate location. This vulnerability applies to DNS server that performs recursive lookups
 
 
 SolutionApply appropriate patches as mentioned in Microsoft Security Bulletin  
                                            
                                                    
												MS07-062 
 Vendor Information Microsoft http://www.microsoft.com/technet/security/bulletin/MS07-062.mspx
 
 References FrSIRThttp://www.frsirt.com/english/advisories/2007/3848
 
 Secunia http://secunia.com/advisories/27584/
 
 SecurityFocus http://www.securityfocus.com/bid/25919/discuss
 
 Xforce http://xforce.iss.net/xforce/xfdb/36805
 
 US-CERT http://www.kb.cert.org/vuls/id/484649
 
 CVE NameDisclaimerCVE-2007-3898
 
 The information provided herein is on "as is" basis, without warranty of any kind. Contact Information  Email: info@cert-in.org.in  Phone: +91-11-2436857 Postal address  Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology
 Government of India
 Electronics Niketan
 6, CGO Complex, Lodhi Road,
 New Delhi - 110 003
 India
   |