Secunia Logo
 
Microsoft Windows NT Denial of Service
Secunia Advisory: SA9337
Release Date: 2003-07-24
Last Update: 2003-08-14
Popularity: 7,797 views

Critical:
Not critical
Impact: DoS
Where: Local system
Solution Status: Vendor Patch

OS:Microsoft Windows NT 4.0 Server
Microsoft Windows NT 4.0 Server, Terminal Server Edition

Subscribe: Instant alerts on relevant vulnerabilities

CVE reference:CVE-2003-0525


Description:
A vulnerability has been identified in Microsoft Windows NT which possibly could allow malicious users to cause certain applications to fail.

The problem is that the file management function may free memory that it doesn't own if it receives a malicious request. This does not affect the operating system but only the application which called the file management function.

Microsoft did not provide any example of an application or configuration which is vulnerable to this issue, but stated that this possibly could affect Internet Information Server 4.0 in a non-default configuration.

Solution:
Patches are avilable:

Microsoft Windows NT 4.0 Server:
http://microsoft.com/downloads/detail...-851F-FFBE2490B901&displaylang=en

Microsoft Windows NT 4.0 Terminal Server Edition:
http://microsoft.com/downloads/detail...-B142-F505BB208797&displaylang=en

Provided and/or discovered by:
Jeremy Rauch, @stake

Changelog:
2003-07-30 Microsoft has issued a hotfix due to problems with the patches on certain configurations.
2003-08-13 New patches released to fix the problem with RRAS configurations.

Original Advisory:
http://www.microsoft.com/technet/security/bulletin/MS03-029.asp


Track this Secunia Advisory
Customers of the Secunia Vulnerability Intelligence solutions will automatically receive updates when new information regarding this advisory is released.

Read more about our Vulnerability Intelligence solutions and what they can do for you and your company.

About this Secunia Advisory
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.

Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
  
Latest Advisories

Send Feedback to Secunia
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.

Ideas, suggestions, and other feedback are most welcome.

Most Popular - 3 Hours

1. Sun Java JDK / JRE Multiple Vulnerabilities // 358 views
2. Adobe Flash Player Multiple Security Issues and Vulnerabilities // 125 views
3. Novell Netware ApacheAdmin Console Security Bypass // 114 views
4. Webboard Street SQL Injection and Information Disclosure // 107 views
5. Null FTP Server "SITE" Parameters Command Injection Vulnerability // 93 views
6. User Engine Lite ASP Database Disclosure // 71 views
7. Trillian Multiple Vulnerabilities // 69 views
8. Tor Two Weaknesses // 67 views
9. Merlix Template Creature "mcatid" SQL Injection Vulnerability // 48 views
10. Avaya Products ed "strip_escapes()" Buffer Overflow Security Issue // 46 views