Privacy and Legal Notice

CIAC INFORMATION BULLETIN

Q-271: Vulnerability in DNS Resolution

[Microsoft Security Bulletin MS06-041 (920683)]

August 8, 2006 20:00 GMT

PROBLEM: There is a remote code execution vulnerability in Winsock and in the DNS Client service.
PLATFORM: Tested Software and Security Update Download Locations:
Affected Software:
• Microsoft Windows 2000 Service Pack 4
• Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service Pack 2
• Microsoft Windows XP Professional x64 Edition
• Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1
• Microsoft Windows Server 2003 for Itanium-based Systems and Microsoft Windows Server 2003 with SP1 for Itanium-based Systems
• Microsoft Windows Server 2003 x64 Edition
DAMAGE: A remote code execution.
SOLUTION: Upgrade to the appropriate version.

VULNERABILITY
ASSESSMENT:
The risk is HIGH. could allow an attacker who successfully exploited this vulnerability to take complete control of the affected system. For an attack to be successful the attacker would have to force the user to open a file or visit a website that is specially crafted to call the affected Winsock API.

LINKS:  
  CIAC BULLETIN: http://www.ciac.org/ciac/bulletins/q-271.shtml
  ORIGINAL BULLETIN: Microsoft Security Bulletin MS06-041
   http://www.microsoft.com/technet/security/bulletin/ms06-041.mspx
  CVE: CVE-2006-3440 CVE-2006-3441

[***** Start Microsoft Security Bulletin MS06-041 (920683) *****]




Quick Links  | Home | Worldwide
Microsoft TechNet
| TechCenters | Downloads | TechNet Program | Subscriptions | My TechNet | Security Bulletins | Archive
Search for

Microsoft Security Bulletin MS06-041

Vulnerability in DNS Resolution Could Allow Remote Code Execution (920683)

Published: August 8, 2006

Version: 1.0

Summary

Who Should Read this Document: Customers who use Microsoft Windows

Impact of Vulnerability: Remote Code Execution

Maximum Severity Rating: Critical

Recommendation: Customers should apply the update immediately

Security Update Replacement: None

Caveats: None

Tested Software and Security Update Download Locations:

Affected Software:

Microsoft Windows 2000 Service Pack 4 — Download the update

Microsoft Windows XP Service Pack 1 and Microsoft Windows XP Service Pack 2 — Download the update

Microsoft Windows XP Professional x64 Edition — Download the update

Microsoft Windows Server 2003 and Microsoft Windows Server 2003 Service Pack 1 — Download the update

Microsoft Windows Server 2003 for Itanium-based Systems and Microsoft Windows Server 2003 with SP1 for Itanium-based Systems — Download the update

Microsoft Windows Server 2003 x64 Edition — Download the update

The software in this list has been tested to determine whether the versions are affected. Other versions either no longer include security update support or may not be affected. To determine the support life cycle for your product and version, visit the Microsoft Support Lifecycle Web site.

Note The security updates for Microsoft Windows Server 2003, Windows Server 2003 Service Pack 1, and Windows Server 2003 x64 Edition also apply to Windows Server 2003 R2.

General Information

Executive Summary

Executive Summary:

This update resolves several newly discovered, privately reported, vulnerabilities.

An attacker who successfully exploited the most severe of these vulnerabilities could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.

We recommend that customers apply this update immediately.

Severity Ratings and Vulnerability Identifiers:

Vulnerability Identifiers Impact of Vulnerability Windows 2000 Windows XP Service Pack 1 Windows XP Service Pack 2 Windows Server 2003 Windows Server 2003 Service Pack 1

Winsock Hostname Vulnerability - CVE-2006-3440

Remote Code Execution

Critical

Critical

Critical

Critical

Critical

DNS Client Buffer Overrun Vulnerability - CVE-2006-3441

Remote Code Execution

Critical

Critical

Critical

Critical

Critical

Aggregate Severity of All Vulnerabilities

 

Critical

Critical

Critical

Critical

Critical

This assessment is based on the types of systems that are affected by the vulnerability, their typical deployment patterns, and the effect that exploiting the vulnerability would have on them.

Note The security updates for Windows Server 2003, Windows Server 2003 Service Pack 1, and Windows Server 2003 x64 Edition also apply to Windows Server 2003 R2.

Note The severity ratings for non-x86 operating system versions map to the x86 operating systems versions as follows:

The Windows XP Professional x64 Edition severity rating is the same as the Windows Server 2003 Service Pack 1 severity rating.

The Windows Server 2003 for Itanium-based Systems severity rating is the same as the Windows Server 2003 severity rating.

The Windows Server 2003 with SP1 for Itanium-based Systems severity rating is the same as the Windows Server 2003 Service Pack 1 severity rating.

The Windows Server 2003 x64 Edition severity rating is the same as the Windows Server 2003 Service Pack 1 severity rating.

Frequently Asked Questions (FAQ) Related to This Security Update

Vulnerability Details

Winsock Hostname Vulnerability - CVE-2006-3440:

There is a remote code execution vulnerability in Winsock that could allow an attacker who successfully exploited this vulnerability to take complete control of the affected system. For an attack to be successful the attacker would have to force the user to open a file or visit a website that is specially crafted to call the affected Winsock API.

Mitigating Factors for Winsock Hostname Vulnerability - CVE-2006-3440:
Workarounds for Winsock Hostname Vulnerability - CVE-2006-3440:
FAQ for Winsock Hostname Vulnerability - CVE-2006-3440:

DNS Client Buffer Overrun Vulnerability - CVE-2006-3441:

There is a remote code execution vulnerability in the DNS Client service that could allow an attacker who successfully exploited this vulnerability to take complete control of the affected system.

Mitigating Factors DNS Client Buffer Overrun Vulnerability - CVE-2006-3441:
Workarounds for DNS Client Buffer Overrun Vulnerability - CVE-2006-3441:
FAQ DNS Client Buffer Overrun Vulnerability - CVE-2006-3441:

Security Update Information

Affected Software:

For information about the specific security update for your affected software, click the appropriate link:

Windows Server 2003 (all versions)