Potential Microsoft PCT worm (MS04-011)

From: advisories (advisories_at_corsaire.com)
Date: 04/23/04

  • Next message: Derek Soeder: "EEYE: Symantec Multiple Firewall TCP Options Denial of Service"
    To: <bugtraq@securityfocus.com>
    Date: Fri, 23 Apr 2004 17:32:50 +0100
    
    

    Potential Microsoft PCT worm (MS04-011)

    A revised exploit has been released for the PCT flaw in the last 24-hrs by
    THC (THCIISSLame.c). For the last few hours we have also been receiving
    uncorroborated anecdotal evidence from reliable sources that a working worm
    is being trialled on the Internet, in preparation for imminent release. The
    primary concern is that this flaw affects unpatched SSL enabled IIS servers,
    which could potentially be thousands of hosts.

    The official Microsoft patch (MS04-011) is strongly recommended for
    immediate application. However, for some organisations, change control and
    software dependency testing have meant that there has not been enough time
    to test and apply the patch widely. Additionally there have been reports of
    some organisations experiencing reliability issues after applying this
    patch, and so they have halted the rollout.

    As time is of the essence, an alternative to applying the patch is available
    by disabling PCT. This option has been tested by Corsaire with the THC
    exploit on Microsoft Windows 2000 SP4 IIS only (but we have no reason to
    doubt that this approach will work just as well on the alternative MS
    platforms).

    There is a Microsoft knowledgebase article that describes the full process.
    Be sure to follow the instructions to the letter, otherwise there is the
    risk that you will still be exposed:
    http://support.microsoft.com/default.aspx?scid=kb;en-us;187498

    -- Background --

    Microsoft Security Bulletin MS04-011 (Microsoft) Microsoft
    http://www.microsoft.com/technet/security/bulletin/ms04-011.mspx

    -- Distribution --

    This security advisory may be freely distributed, provided that it
    remains unaltered and in its original form.

    -- Disclaimer --

    The information contained within this advisory is supplied "as-is" with
    no warranties or guarantees of fitness of use or otherwise. Corsaire
    accepts no responsibility for any damage caused by the use or misuse of
    this information.

    Copyright 2004 Corsaire Limited. All rights reserved.


  • Next message: Derek Soeder: "EEYE: Symantec Multiple Firewall TCP Options Denial of Service"

    Relevant Pages

    • [Full-Disclosure] Potential Microsoft PCT worm (MS04-011)
      ... Potential Microsoft PCT worm ... A revised exploit has been released for the PCT flaw in the last 24-hrs by ... to test and apply the patch widely. ... This option has been tested by Corsaire with the THC ...
      (Full-Disclosure)
    • Re: [Full-disclosure] Security Alert: Unofficial IE patches appear on internet
      ... created by a vulnerability is as serious as this case and the available ... Microsoft will be inclined strongly against holding on to this patch. ... Microsoft often have patches ready but wait for the corporate known ...
      (Full-Disclosure)
    • Re: Worm in Patch
      ... a naive and trusting nature in your personality believing that you would ... "receive a patch" instead of getting it from a trusted source..? ... Essentially - Microsoft never emails you a patch. ... using Windows XP "prettifications". ...
      (microsoft.public.windowsxp.security_admin)
    • Re: Why do i keep on receiving shutdown system ?
      ... the Microsoft provided information on the matter can be ... The Symantec Repair utility and manual removal instructions can be found ... The patch that would have prevented this whole fiasco for you: ... If you have Sasser, the Microsoft provided information on the matter can be ...
      (microsoft.public.windowsxp.security_admin)
    • Re: NT Authority..
      ... You could have Blaster or you could have Sasser. ... the Microsoft provided information on the matter can be ... The patch that would have prevented this whole fiasco for you: ... After enabling the Internet Connection Firewall or creating the read-only ...
      (microsoft.public.windowsxp.help_and_support)