CERT-In Vulnerability Note
CIVN-2014-0248
Remote Code Execution Vulnerability in Microsoft Schannel
Original Issue Date:November 12, 2014
Severity Rating: HIGH
Systems Affected
- Microsoft Windows Vista Service Pack 2 0
- Microsoft Windows Server 2008 R2 for x64-based Systems SP1
- Microsoft Windows Server 2008 for 32-bit and x64-based Systems SP2
- Microsoft Windows Server 2008 for Itanium-based Systems SP2
- Microsoft Windows Server 2003 Itanium SP2
- Microsoft Windows Server 2003 SP2
- Microsoft Windows 7 for x64-based Systems SP1
- Microsoft Windows 7 for 32-bit Systems SP1
Overview
A remote code execution vulnerability has been reported in Microsoft Secure Channel (Schannel) security package which could allow a remote attacker to execute arbitrary code on the targeted system.
Description
Secure Channel, also known as Schannel, is a security support provider (SSP) that contains a set of security protocols that provide identity authentication and secure, private communication through encryption. Schannel is primarily used for Internet applications that require secure Hypertext Transfer Protocol (HTTP) communications
A remote code execution vulnerability exists in the Microsoft Secure Channel (Schannel) security package due to improper handling of specially crafted packets. A remote attacker could exploit this vulnerability by sending crafted packets to a targeted system.Successful exploitation could allow the attacker to execute arbitrary code on the targeted system.
Solution
Apply appropriate updates as mentioned in the Microsoft Security Bulletin
MS14-066
Vendor Information
Microsoft
https://technet.microsoft.com/en-us/library/security/ms14-066
References
Microsoft
https://technet.microsoft.com/en-us/library/security/ms14-066
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=36256
Security Focus
http://www.securityfocus.com/bid/70954
CVE Name
CVE-2014-6321
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|