CERT-In Vulnerability Note
CIVN-2009-0148
Microsoft Windows Active Directory Federation Services Remote Code Execution Vulnerabilities
Original Issue Date:December 09, 2009
Severity Rating: MEDIUM
Systems Affected
- Windows Server 2003 Service Pack 2
- Windows Server 2003 x64 Edition Service Pack 2
- Windows Server 2008 for 32-bit Systems
- Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Server 2008 for x64-based Systems
- Windows Server 2008 for x64-based Systems Service Pack 2
Overview
A vulnerability exists in Microsoft Windows Local Security Authority Subsystem Service LSASS which could allow remote attacker to cause Denial of Service DoS condition on an affected system.
Description
1. Single Sign On Spoofing in ADFS Vulnerability
(
CVE-2009-2508
)
This vulnerability is caused due to improper session management routines in ADFS. The authentication services fail to terminate a users session after the user logs out. An attacker with local access to a system on which the user has previously logged in via ADFS could exploit this vulnerability to resume a users session to a web application. As a result, the attacker could take actions on the website with the privileges of the user.
2. Remote Code Execution in ADFS Vulnerability
(
CVE-2009-2509
)
This vulnerability is caused due to improper processing of request headers within messages exchanged between a user and the ADFS. An authenticated, remote attacker could exploit this vulnerability by sending a malicious request to the vulnerable system running vulnerable services. While processing, the request could allow the attacker to execute arbitrary code on the system with the privileges of ADFS.
Workaround
- Disable the IPsec service if not in use
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin
MS09-070
Vendor Information
Microsoft
http://www.microsoft.com/technet/security/bulletin/MS09-070.mspx
References
CISCO
http://tools.cisco.com/security/center/viewAlert.x?alertId=19516
http://tools.cisco.com/security/center/viewAlert.x?alertId=19517
SecurityTracker
http://securitytracker.com/alerts/2009/Dec/1023296.html
SecurityFocus
http://www.securityfocus.com/bid/37215
http://www.securityfocus.com/bid/37214
CVE Name
CVE-2009-2508
CVE-2009-2509
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|