Executive Summary
| Summary | |
|---|---|
| Title | Microsoft IIS FTP server memory corruption vulnerability |
| Informations | |||
|---|---|---|---|
| Name | VU#842372 | First vendor Publication | 2010-12-22 |
| Vendor | VU-CERT | Last vendor Modification | 2010-12-23 |
| Severity (Vendor) | N/A | Revision | M |
Security-Database Scoring CVSS v2
| Cvss vector : (AV:N/AC:L/Au:N/C:C/I:C/A:C) | |||
|---|---|---|---|
| Cvss Base Score | 10 | Attack Range | Network |
| Cvss Impact Score | 10 | Attack Complexity | Low |
| Cvss Expoit Score | 10 | Authentification | None Required |
| Calculate full CVSS 2.0 Vectors scores | |||
Detail
Vulnerability Note VU#842372Microsoft IIS FTP server memory corruption vulnerabilityOverviewMicrosoft IIS FTP server 7.5 is affected by a pre-authentication memory corruption vulnerability.I. DescriptionA specifically crafted request sent to the IIS FTP service can result in memory corruption causing the service to crash. A denial-of-service exploit has been released to the public. IIS 7.5.7600.16385 on Windows 7 is reported to be affected. Other versions may also be affected. Additional details are available on Microsoft's Security Research & Defense blog.II. ImpactAn attacker can cause a denial of service. Depending on the specifics of the vulnerability, an attacker could potentially execute arbitrary code.III. SolutionWe are currently unaware of a practical solution to this problem.Restrict Access Vendor Information
Referenceshttp//blogs.technet.com/b/srd/archive/2010/12/22/assessing-an-iis-ftp-7-5-un... CreditThis vulnerability was reported to the public by Matthew Bergin via Exploit-DB. This document was written by Jared Allar. Other Information
|
Original Source
| Url : http://www.kb.cert.org/vuls/id/842372 |
CWE : Common Weakness Enumeration
| id | Name |
|---|---|
| CWE-119 | Failure to Constrain Operations within the Bounds of a Memory Buffer |
OVAL Definitions
| Definition Id: oval:org.mitre.oval:def:12370 | |||
| Oval ID: | oval:org.mitre.oval:def:12370 | ||
| Title: | IIS FTP Service Heap Buffer Overrun Vulnerability | ||
| Description: | Heap-based buffer overflow in the TELNET_STREAM_CONTEXT::OnSendData function in ftpsvc.dll in Microsoft FTP Service 7.0 and 7.5 for Internet Information Services (IIS) 7.0, and IIS 7.5, allows remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via a crafted FTP command, aka "IIS FTP Service Heap Buffer Overrun Vulnerability." NOTE: some of these details are obtained from third party information. | ||
| Family: | windows | Class: | vulnerability |
| Reference(s): | CVE-2010-3972 |
Version: | 7 |
| Platform(s): | Microsoft Windows Vista Microsoft Windows 7 Microsoft Windows Server 2008 Microsoft Windows Server 2008 R2 |
Product(s): | Microsoft FTP Service 7.0 Microsoft FTP Service 7.5 |
| Definition Synopsis: | |||
|
|||
CPE : Common Platform Enumeration
| Type | Description | Count |
|---|---|---|
| Application | 1 |
Open Source Vulnerability Database (OSVDB)
| id | Description |
|---|---|
| 70167 | Microsoft IIS FTP Server Telnet IAC Character Handling Overflow |
Metasploit Database
| id | Description |
|---|---|
| 2010-12-21 | Microsoft IIS FTP Server Encoded Response Overflow Trigger |

VU#842372
(Critical)







