Secunia Logo
 
Microsoft Proxy Server 2.0 / ISA Server 2000 Denial of Service
Secunia Advisory: SA8560
Release Date: 2003-04-09
Last Update: 2003-04-10
Popularity: 7,963 views

Critical:
Less critical
Impact: DoS
Where: From local network
Solution Status: Vendor Patch

Software:Microsoft ISA Server 2000
Microsoft Proxy Server 2.x

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2003-0110


Description:
A vulnerability in Microsoft Proxy Server 2.0 and ISA Server 2000 can be exploited by malicious people to cause a DoS (Denial of Service) on a vulnerable system.

The vulnerability is caused by an exceptional handling error in the Winsock Proxy service. This can be exploited by a malicious person on the internal network by sending a specially crafted packet to the server, which will utilize 100% of the CPU resources.

Successful exploitation results in the server becoming unresponsive, which makes it impossible for traffic to pass through the server. The Winsock Proxy service would have to be restarted to regain functionality.

The vulnerability could also be exploited from the Internet. However, this requires that the system is configured to accept packets to port 1745/udp, which would have to be configured specifically, since these are blocked by default.

Solution:
Apply patch:

-- Proxy Server 2.0 (with SP1 installed) --

http://microsoft.com/downloads/detail...-BAFD-031A0D2923E6&displaylang=en


-- ISA Server 2000 (with SP1 or FP1 installed) --

English:
http://microsoft.com/downloads/detail...84B7-1053C8663436&displaylang=en

French:
http://microsoft.com/downloads/detail...84B7-1053C8663436&displaylang=fr

German:
http://microsoft.com/downloads/detail...84B7-1053C8663436&displaylang=de

Spanish:
http://microsoft.com/downloads/detail...84B7-1053C8663436&displaylang=es

Japanese:
http://microsoft.com/downloads/detail...-84B7-1053C8663436&displaylang=ja

Original Advisory:
http://www.microsoft.com/technet/security/bulletin/MS03-012.asp


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. ClamAV "cli_check_jpeg_exploit()" Denial of Service Vulnerability // 56 views
2. Linksys WRT160N Cross-Site Scripting Vulnerability // 49 views
3. IBM Rational ClearCase Cross-Site Scripting Vulnerability // 48 views
4. IBM Rational ClearQuest Multiple Vulnerabilities // 41 views
5. Mozilla Firefox 3 Multiple Vulnerabilities // 41 views
6. Sun Java JDK / JRE Multiple Vulnerabilities // 40 views
7. DAHDI "ZT_SPANCONFIG" IOCTL Privilege Escalation Vulnerability // 39 views
8. Rumpus Multiple Vulnerabilities // 38 views
9. bcoos "cid" SQL Injection Vulnerability // 38 views
10. Debian update for flamethrower // 38 views