Outpost 個人防火牆 - Plug and Play vulnerability May Lead to Remote Code Execution and Privilege Elevation
Agnitum Security Advisories
ASA-05-0508-4: Plug and Play vulnerability May Lead to Remote Code Execution and Privilege Elevation
Vulnerability summary:
|
Severity rating:
|
Critical
|
|
|
Date Published:
|
August 9, 2005
|
|
|
Software Vendor:
|
Microsoft
|
|
|
Affected Software:
|
Plug and Play (PnP) component
|
|
|
Affected OS:
|
Windows 2000 (all), Windows XP (all), Windows Server 2003 (all)
|
|
|
Unaffected with:
|
-
|
|
|
Vulnerability class:
|
Remote Code Execution, Privilege Elevation
|
|
|
Status:
|
Fixed
|
Vulnerability details:
Tech brief:
An arbitrary code can be executed on a remote computer vulnerable to the PnP exploit. An attacker who successfully exploits this vulnerability can take complete control over the affected system – install programs; view, change, or delete data; or create new accounts with full user rights.
Plug and Play (PnP) allows the operating system to detect new hardware when it is being installed on a system. For example, when you install new mouse on your computer, PnP lets Windows detect it, load the necessary drivers, and then proceed to the using of the new device automatically.
To try to exploit this vulnerability, an anonymous attacker can create a specially crafted message and send it to an affected system. The message could then cause the affected system to execute code.
Vendor reference information:
Vendor details pertaining to the problem are available here:
http://www.microsoft.com/technet/security/bulletin/MS05-039.mspx
General Mitigating Recommendations
Install latest vendor patches available at http://windowsupdate.microsoft.com
How the Outpost Firewall PRO protects you:
You can limit the communication over TCP ports 139 and 445 so that only members of your trusted network can exchange data over those ports utilized by the vulnerable PnP module. It will prevent possible attacks from the Internet or any other location outside of your trusted perimeter while allowing PnP communication to legitimate users.
Disclaimer:
Information in the present advisory is believed to be accurate as to the time of publishing based on currently available information. Use of the information signifies acceptance for use in an AS IS condition. There are no warranties with regard to this information. Agnitum Ltd. doesn't accept any liability for any direct, indirect, or consequential loss or damage arising from use of, or reliance on, this information.
關於Version 2 Limited
Version 2 Limited 是亞洲其中一間最有活力的IT公司,公司發展及代理各種不同的互聯網及IP-Based 網絡IT產品,當中包括通訊系統、保安、網絡及媒體產品。透過公司龐大的網絡、銷售點、分銷商及合作顆伴,Version 2 Limited 便可提供廣被市場讚賞的產品及服務。Version 2 Limited 客戶來自各行各業,包括全球1000大跨國企業、上市公司、公用機構、政府部門、無數成功的中小企及來自亞洲各城市的客戶。
如對產品有興趣,可瀏覽以下網址:
http://www.version-2.com/op
http://www.version-2.com/nod32op
![]()

台灣
RSS

