CERT-In Vulnerability Note
CIVN-2009-0147
Microsoft Local Security Authority Subsystem Service Denial of Service Vulnerability
Original Issue Date:December 09, 2009
Severity Rating: MEDIUM
Systems Affected
- Microsoft Windows 2000 Service Pack 4
- Windows XP Service Pack 2
- Windows XP Service Pack 3
- Windows XP Professional x64 Edition Service Pack 2
- Windows Server 2003 Service Pack 2
- Windows Server 2003 x64 Edition Service Pack 2
- Windows Server 2003 with SP2 for Itanium-based Systems
Overview
A vulnerability exists in Microsoft Windows Local Security Authority Subsystem Service LSASS which could allow remote attacker to cause Denial of Service DoS condition on an affected system.
Description
The Local Security Authority Subsystem Service LSASS in Microsoft Windows provides an interface for managing local security, domain authentication, and Active Directory service processes. LSASS handles authentication for the client and for the server and also contains features for supporting Active Directory utilities.
This vulnerability is caused due to error while handling Internet Security Association and Key Management Protocol ISAKMP messages by LSASS using Internet Protocol security IPSec communication. An authenticated, remote attacker could exploit the vulnerability by sending a malicious ISAKMP message during an established and authenticated IPsec session. The processing of a malformed message could cause the LSASS to consume available CPU resources, causing the system unresponsive and resulting a DoS condition on vulnerable system.
Workaround
- Disable the IPsec service if not in use
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin
MS09-069
Vendor Information
Microsoft
http://www.microsoft.com/technet/security/Bulletin/MS09-069.mspx
References
CISCO
http://tools.cisco.com/security/center/viewAlert.x?alertId=19504
SecurityTracker
http://securitytracker.com/alerts/2009/Dec/1023297.html
SecurityFocus
http://www.securityfocus.com/bid/37218
VUPEN
http://www.vupen.com/english/advisories/2009/3433
CVE Name
CVE-2009-3675
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|