[Snort-sigs] Denial of Service (DoS) in Microsoft SMS Client Signature

Terence Runge terencerunge at ...1224...
Wed Jul 14 14:02:22 EDT 2004

In reference to the SMS Client DoS made public on Full Disclosure today 
I put together a quick signature. Please modify / improve at will.

alert tcp any any -> $HOME_NET 2702 (msg:"SMS Client DoS Attempt"; 
content:"RCHO####RCHE"; flow:to_client,established; 
classtype:attempted-dos; sid:7130410; rev:1;)



Denial of Service (DoS) in Microsoft SMS Client

Level: low-[MED]-high-crit
ID: HEXVIEW*2004*07*14*1

Microsoft Systems Management Server provides configuration management
solution for Windows platform. It is widely deployed in medium and large
network environments. A flaw in SMS Remote Control service makes possible to
crash the service remotely leading to the DoS condition.

Affected products:
All tests were performed on a client part of Microsoft Systems Management
Server version 2.50.2726.0.

Cause and Effect:
SMS Remote Control Client service is listening on TCP ports 2701 and 2702.
The service performs basic signature checks and size tests on received data
and assumes the data is correct if those tests pass. It is possible to 
a data packet that will go through basic checks and throw an exception by
causing the server to read or write to an invalid memory address. It is also
possible to specify the memory address value in the data packet.
Initial analysis showed that the problem is not [easily] exploitable because
there is no buffer overflow condition and it is not possible to specify the
data to be written to the memory. The exception occurs in multprot.dll
library when the service makes an API call with invalid parameters.

The problem can be reproduced by sending the "RCH0####RCHE" string 
followed by
a large number of characters (over 130) to TCP port 2702.

Vendor Status:
At the time of release vendor was not aware of the vulnerability.
HexView does not notify vendors unless there is a prior agreement to do so.
Vendors interested in receiving notifications prior to public disclosure
or more detailed analysis may obtain more information by writing to the
e-mail address provided at the end of the document.

About HexView:
HexView contributes to online security-related lists for almost a decade.
The scope of our expertize spreads over Windows, Linux, Sun, MacOS 
network applications, and embedded devices. The chances are you read our
advisories or disclosures. For the sake of readability and easy web indexing
we recently decided to use the HexView alias to publish all the information.

This document may be freely distributed through any channels as long as the
contents are kept unmodified. Commercial use of the information in the 
is not allowed without written permission from HexView signed by our pgp 

Feedback and comments:
Feedback and questions about this disclosure are welcome at 
vtalk at ...2631...

Version: GnuPG v1.2.4 (GNU/Linux)


Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html

More information about the Snort-sigs mailing list