ie8 fix
madison

Zero Day

Ryan Naraine, Emil Protalinski and Dancho Danchev

Microsoft fixes gaping hole in Windows TCP/IP stack

By | November 8, 2011, 10:39pm PST

Summary: An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode. Microsoft urges Windows users to treat this update with the utmost priority.

Microsoft has released its November batch of security bulletins with fixes for at least four documented vulnerabilities affecting the Windows operating system.

The updates address remote code execution and denial-of-service issues in all versions of Windows and Microsoft is urging its user base to pay special attention to MS11-083, which covers a gaping hole in the Windows TCP/IP stack.

The raw details:

A remote code execution vulnerability exists in the Windows TCP/IP stack due to the processing of a continuous flow of specially crafted UDP packets. An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.

Because of the “critical” nature of this update, Microsoft is urging Windows users and administrators to treat MS11-083 with the utmost priority.

follow Ryan Naraine on twitter

The company also fixed a serious vulnerability in Windows Mail that exposes users to hacker attacks via the Web browser.

Some basic details via the MS11-085 bulletin:

The vulnerability could allow remote code execution if a user opens a legitimate file (such as an .eml or .wcinv file) that is located in the same network directory as a specially crafted dynamic link library (DLL) file. Then, while opening the legitimate file, Windows Mail or Windows Meeting Space could attempt to load the DLL file and execute any code it contained. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a legitimate file (such as an .eml or .wcinv file) from this location that is then loaded by a vulnerable application.

Microsoft expects to see functional exploit code for this vulnerability within the next 30 days.

The November Patch Tuesday batch also contains fixes for a privilege escalation flaw in Active Directory (MS11-086) and a vulnerability in Windows kernel mode drivers (MS11-084) that could allow denial-of-service attacks.

Kick off your day with ZDNet's daily e-mail newsletter. It's the freshest tech news and opinion, served hot. Get it.

Topics

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues.

Disclosure

Ryan Naraine

The most important disclosure is of my employment with Kaspersky Lab as a member of the global research and analysis team. Kaspersky Lab is a global company specializing in anti-malware and secure content management technologies. I do not own stocks or other investments in any technology company.

Biography

Ryan Naraine

Ryan Naraine is a journalist and social media enthusiast specializing in Internet and computer security issues. He is currently security evangelist at Kaspersky Lab, an anti-malware company with operations around the globe. He is taking a leadership role in developing the company's online community initiative around secure content management technologies.

Prior to joining Kaspersky Lab, Ryan was Editor-at-Large/Security at eWEEK, leading the magazine's and Web site's coverage of Internet and computer security issues and managing the popular SecurityWatch blog, covering the daily threats, vulnerabilities and IT security technologies. He also covered IT security, hacker attacks and secure content management topics for Jupiter Media's internetnetnews.com.

Ryan can be reached at naraine SHIFT 2 gmail.com. For daily updates on Ryan's activities, follow him on Twitter.

33
Comments

Join the conversation!

Just In

dsf
jywhy888 7th Mar
Eye Mask Wholesale Coaster http://www.chinawholesaletown.com/wholesale-Digital-Photo-Frame/ Photo Frame
Wholesale Frisbee World Cup Products http://www.chinawholesaletown.com/ Gift Bags
Pen Holder Wholesale Clothes Rack http://www.chinawholesaletown.com/wholesale-iPod---iPhone/ Flag
Promotional Gifts Wholesale Waterproof Case http://www.chinawholesaletown.com/wholesale-Bottle-Opener/ Garden Decorations
Vocal Concert Products Stuffed Animals http://www.chinawholesaletown.com/wholesale-Heating-Products/ Digital Photo Frame
Name Card Holder Wholesale Scissors http://www.chinawholesaletown.com/wholesale-Knife/ Lanyard
Wholesale Lanyard Wholesale Pin http://www.chinawholesaletown.com/ Book Light
Outdoor Leisure Products Electrical Gifts http://www.chinawholesaletown.com/wholesale-Fishing/ Mouse Pad
Wholesale Calendar Wholesale Racks http://www.chinawholesaletown.com/wholesale-Apron/ Jewelry
Wholesale Bracelet Silicone Products http://www.chinawholesaletown.com/wholesale-Medicine-Instrument/ Fan
Wholesale Puzzle Wholesale Massager http://www.chinawholesaletown.com/wholesale-Furniture/ Tableware
Wine Set Industrial Supplies http://www.chinawholesaletown.com/wholesale-Pen-Holder/ Scarf
Wholesale Scissors Wholesale Lighter http://www.chinawholesaletown.com/wholesale-Jewelry/ Heating Products
Lunch Box Wholesale Mouse http://www.chinawholesaletown.com/wholesale-Clothes-Rack/ Wedding Favors
Wholesale Flashlight Wholesale Helmet http://www.chinawholesaletown.com/wholesale-MP3---MP4---MP5-Player/ lable
Business Gift Health Care Products http://www.chinawholesaletown.com/wholesale-Stapler/ Whistle
Wholesale Album Wholesale Apron http://www.chinawholesaletown.com/wholesale-Valentine-Gifts/ Promotional Gifts
Wholesale Racks Wholesale Memory Card http://www.chinawholesaletown.com/wholesale-Poncho-Raincoat/ Reflective Safety Vest
Poncho Raincoat Wholesale Mp3 http://www.chinawholesaletown.com/wholesale-Glasses/ Mobile Phone
Health Care Products Wholesale Hardware Tools http://www.chinawholesaletown.com/wholesale-Recorder-Pen/ Pin
Wholesale Umbrella Electroluminescent http://www.chinawholesaletown.com/wholesale-Entertainment/ First Aid Kit
Wholesale Swimming Products Wholesale TelePhone http://www.chinawholesaletown.com/wholesale-USB-Products/ Sticker
Wholesale Kitchenware Wholesale Tag http://www.chinawholesaletown.com/wholesale-First-Aid-Kit/ Cards
Wholesale Sticker Wholesale Stationery http://www.chinawholesaletown.com/wholesale-Waterproof-Case/ Poncho
Wholesale Towel Entertainment Supplies http://www.chinawholesaletown.com/wholesale-Dartboard/ Dartboard
Wholesale Gift Bags Voice Recorder http://www.chinawholesaletown.com/wholesale-Bracelet---Bangle/ Promotional Products
Wholesale Mat Money Clip http://www.chinawholesaletown.com/wholesale-Silicone/ Pet Supplies
Tape Measure Wholesale Sticker http://www.chinawholesaletown.com/wholesale-Halloween-Gift/ Lighter
Gift Box Beauty Equipment http://www.chinawholesaletown.com/wholesale-Belt/ Tie
Baby Products Suppliers CD Holde http://www.chinawholesaletown.com/wholesale-Whistle/ Towel
Wholesale Tableware Vocal Concert Products http://www.chinawholesaletown.com/wholesale-Bracelet---Bangle/ Lighting Products
Wholesale First Aid Kit Wholesale Scarf http://www.chinawholesaletown.com/wholesale-Lanyard/ Glass
Garden Decorations Wholesale Speakers http://www.chinawholesaletown.com/wholesale-Bag/ Frisbee
Entertainment Supplies Wholesale Compass http://www.chinawholesaletown.com/wholesale-Consumer-Electronics/ Scissors
Wholesale Memory Card Wholesale Knife http://www.chinawholesaletown.com/wholesale-Mouse/ Massager
Wholesale Radio Giveaway Material http://www.chinawholesaletown.com/wholesale-Sticker/ Money Bank
I love this site. Every security patch fixes a 'Gaping Hole'. Seems like MacOSX and Windows are 'Swiss Cheese' and a glass house with no glass.
when he talks about OS X. However, don't underestimate the severity of the TCP/IP stack hole. This is the kind of security exploit Windows is famous for. No social engineering, just turn on the computer, connect to the internet and you can be pwned. This is the SECOND such exploit Windows 7 has had. The last one was a hole in their bluetooth stack. Go to starbucks, turn on your laptop and every computer within 60 feet could potentially pwn your system without you knowing it.
0 Votes
+ -
Not an exploit, a vulnerability
Doctor Demento 9th Nov
@baggins_z

There has never been any successful 'exploit' of the Bluetooth error that I am aware of, only a vulnerability that was patched before an exploit entered the wild. If you are aware of an exploit, some documentation would be nice.
0 Votes
+ -
Not an exploit, a vulnerability
Doctor Demento Updated - 9th Nov
Triple post error
0 Votes
+ -
Not an exploit, a vulnerability
Doctor Demento Updated - 9th Nov
triple post error
0 Votes
+ -
Security hole vs. exploit.
baggins_z 9th Nov
You can't have the second without the first, so, yeah, it's still very serious.
@baggins_z

When will a hacker engaged in illegal activity exploiting vulnerabilities ever go out of his/her way to document an exploit for you?
0 Votes
+ -
dsf
jywhy888 7th Mar
Eye Mask Wholesale Coaster http://www.chinawholesaletown.com/wholesale-Digital-Photo-Frame/ Photo Frame
Wholesale Frisbee World Cup Products http://www.chinawholesaletown.com/ Gift Bags
Pen Holder Wholesale Clothes Rack http://www.chinawholesaletown.com/wholesale-iPod---iPhone/ Flag
Promotional Gifts Wholesale Waterproof Case http://www.chinawholesaletown.com/wholesale-Bottle-Opener/ Garden Decorations
Vocal Concert Products Stuffed Animals http://www.chinawholesaletown.com/wholesale-Heating-Products/ Digital Photo Frame
Name Card Holder Wholesale Scissors http://www.chinawholesaletown.com/wholesale-Knife/ Lanyard
Wholesale Lanyard Wholesale Pin http://www.chinawholesaletown.com/ Book Light
Outdoor Leisure Products Electrical Gifts http://www.chinawholesaletown.com/wholesale-Fishing/ Mouse Pad
Wholesale Calendar Wholesale Racks http://www.chinawholesaletown.com/wholesale-Apron/ Jewelry
Wholesale Bracelet Silicone Products http://www.chinawholesaletown.com/wholesale-Medicine-Instrument/ Fan
Wholesale Puzzle Wholesale Massager http://www.chinawholesaletown.com/wholesale-Furniture/ Tableware
Wine Set Industrial Supplies http://www.chinawholesaletown.com/wholesale-Pen-Holder/ Scarf
Wholesale Scissors Wholesale Lighter http://www.chinawholesaletown.com/wholesale-Jewelry/ Heating Products
Lunch Box Wholesale Mouse http://www.chinawholesaletown.com/wholesale-Clothes-Rack/ Wedding Favors
Wholesale Flashlight Wholesale Helmet http://www.chinawholesaletown.com/wholesale-MP3---MP4---MP5-Player/ lable
Business Gift Health Care Products http://www.chinawholesaletown.com/wholesale-Stapler/ Whistle
Wholesale Album Wholesale Apron http://www.chinawholesaletown.com/wholesale-Valentine-Gifts/ Promotional Gifts
Wholesale Racks Wholesale Memory Card http://www.chinawholesaletown.com/wholesale-Poncho-Raincoat/ Reflective Safety Vest
Poncho Raincoat Wholesale Mp3 http://www.chinawholesaletown.com/wholesale-Glasses/ Mobile Phone
Health Care Products Wholesale Hardware Tools http://www.chinawholesaletown.com/wholesale-Recorder-Pen/ Pin
Wholesale Umbrella Electroluminescent http://www.chinawholesaletown.com/wholesale-Entertainment/ First Aid Kit
Wholesale Swimming Products Wholesale TelePhone http://www.chinawholesaletown.com/wholesale-USB-Products/ Sticker
Wholesale Kitchenware Wholesale Tag http://www.chinawholesaletown.com/wholesale-First-Aid-Kit/ Cards
Wholesale Sticker Wholesale Stationery http://www.chinawholesaletown.com/wholesale-Waterproof-Case/ Poncho
Wholesale Towel Entertainment Supplies http://www.chinawholesaletown.com/wholesale-Dartboard/ Dartboard
Wholesale Gift Bags Voice Recorder http://www.chinawholesaletown.com/wholesale-Bracelet---Bangle/ Promotional Products
Wholesale Mat Money Clip http://www.chinawholesaletown.com/wholesale-Silicone/ Pet Supplies
Tape Measure Wholesale Sticker http://www.chinawholesaletown.com/wholesale-Halloween-Gift/ Lighter
Gift Box Beauty Equipment http://www.chinawholesaletown.com/wholesale-Belt/ Tie
Baby Products Suppliers CD Holde http://www.chinawholesaletown.com/wholesale-Whistle/ Towel
Wholesale Tableware Vocal Concert Products http://www.chinawholesaletown.com/wholesale-Bracelet---Bangle/ Lighting Products
Wholesale First Aid Kit Wholesale Scarf http://www.chinawholesaletown.com/wholesale-Lanyard/ Glass
Garden Decorations Wholesale Speakers http://www.chinawholesaletown.com/wholesale-Bag/ Frisbee
Entertainment Supplies Wholesale Compass http://www.chinawholesaletown.com/wholesale-Consumer-Electronics/ Scissors
Wholesale Memory Card Wholesale Knife http://www.chinawholesaletown.com/wholesale-Mouse/ Massager
Wholesale Radio Giveaway Material http://www.chinawholesaletown.com/wholesale-Sticker/ Money Bank
Why? Please note, that's an exasperated "why" not one that even begins to want to know why!
0 Votes
+ -
@ego.sum.stig@... Really, where do you want the network stack to run, in user mode? Maybe have one stack for every process?
WHY don't you learn basic OS design and concepts, that's an exasperated "why"
0 Votes
+ -
RE: Microsoft fixes gaping hole in Windows TCP/IP stack
Return_of_the_jedi Updated - 9th Nov
@TardHugger@...

When they STOLE the code from BSD,
maybe they should have implemented it as BSD did.
Hence Windows only problem, again.
  • Flagged
@Return_of_the_jedi: When they STOLE the code from BSD, maybe they should have implemented it as BSD did.

You failed to address his point. Perhaps because of the following statement of his is obviously accurate:

"WHY don't you learn basic OS design and concepts, that's an exasperated "why"
0 Votes
+ -
@Return_of_the_jedi wrote:
"When they STOLE the code from BSD, maybe they should have implemented it as BSD did.

I've seen various postings on the internet that Microsoft both did and did not use the TCP/IP stack from BSD in Windows. If they indeed did use it, they did not steal it as BSD has a permissive license.

If one wants to be sure they are using a BSD port of ipfw, then they can download, install and configure wipfw from here:

http://wipfw.sourceforge.net/index.html
@Return_of_the_jedi

Do a little research on the HUNDREDS of security problems that have been found in Unix BIND over the years
0 Votes
+ -
Because?
ego.sum.stig@... 10th Nov
Maybe you perhaps missed the key word "stuff." I suggest glasses and an attitude adjustment. That and as far as your supposed superior knowledge on OS design, well, no. Now tootle along and get angry at someone else who might (if you're really lucky) choose to compare you unfavourably to curdled milk.
famous for. A TCP/IP stack exploit means you turn on your computer, you connect to the internet, and DOING NOTHING ELSE, you can get potentially pwned.
0 Votes
+ -
Not really.
ye 9th Nov
@baggins_z: This is the type of security hole that Windows is famous for.

As you said above...it's only the second such type of vulnerability in two years. Hardly an earth shattering record.
0 Votes
+ -
Happened to me once
John L. Ries Updated - 9th Nov
@baggins_z
And it was a Windows box (a laptop running Windows XP, to be exact) it happened to. Very scary.

Response to ChoMo:

Positive. I don't remember the exact nature of the malware installed (it literally happened within minutes of booting up the machine), but I had to completely reinstall Windows from scratch that night (this was about 8 years ago).

Reply to PollyProteus:

Thanks for dating it. SP1 worked just fine for me. This happened right *before* SP2 was released.
@John L. Ries
Are you sure it wasn't a "user" virus?
@John L. Ries - Eight years ago would have been around the Windows XP SP1 time frame and I'm pretty sure it was something else as I remember having to flatten new machines, install off the network, enable the Windows firewall and then connect to the network. Not a happy experience and it took IT months to finally squash it.
@baggins_z Are UDP packets allowed by routers on the internet?
0 Votes
+ -
@TardHugger: What's not clear to me is whether the built in firewall block this type of attack.
@TardHugger@: What's not clear to me is if the built in firewall blocks this attack vector.


Damn forum software erased my previous post!
@TardHugger@...
Absolutely! (allowed on the Internet).
And unlike TCP/IP traffic, many home routers are more permissive to UDP port traffic that appears to be in response to activity initiated on the inside than they are to TCP/IP traffic. (In order to not break stuff - like gaming - given the connectionless nature of the UDP protocol.)

I'd be less likely to "trust" a consumer grade firewall to protect me from this exploit than most, because it's UDP based.
0 Votes
+ -
They have to be
John L. Ries Updated - 9th Nov
@TardHugger@...
There are too many protocols that depend on UDP.

To ghastly: UDP is an integral part of the TCP/IP suite and has been from the very beginning.
@John L. Ries: UDP is an integral part of the TCP/IP suite and has been from the very beginning.

It's TCP/IP or UDP/IP. TCP and UDP reside at the same level on the OSI model.
0 Votes
+ -
Windows XP Immune
Spikey_Mike 9th Nov
Imagine that!
0 Votes
+ -
BSD stolen code
spamsucks 9th Nov
The BSD TCP/IP was "stolen" in the sense that it was used and used uncredited as required by the license. (The license actually allows anyone to use the code). As so far as to why only Win7 was affected is because with Vista they took all the BSD code out and rewrote it themselves. So Vista and 7 no longer contains the BSD code.
...when you see this kinds of "issues in all versions of Windows" in a functionality that was supposed to have been redone for Vista and 7, you start wondering if the famous "Windows 7 is more secure" pitch is just that--a sales pitch--and not really something the OS team had in mind when they developed the new NT kernel.
@cosuna It does become hard to believe Vista/7/2008 are based on an "entirely new code base" doesn't it.
@anothercanuck
The TCP/IP stack vulnerability exists only in Vista, 7 and Server 2008 - hence it is presumably a vulnerability in the new TCP/IP stack code that was implemented in Vista.
Refer to: http://technet.microsoft.com/en-us/security/bulletin/ms11-083

Join the conversation!

Formatting +
BB Codes - Note: HTML is not supported in forums
  • [b] Bold [/b]
  • [i] Italic [/i]
  • [u] Underline [/u]
  • [s] Strikethrough [/s]
  • [q] "Quote" [/q]
  • [ol][*] 1. Ordered List [/ol]
  • [ul][*] · Unordered List [/ul]
  • [pre] Preformat [/pre]
  • [quote] "Blockquote" [/quote]
ie8 fix
Click Here
ie8 fix

The best of ZDNet, delivered

ZDNet Newsletters

Get the best of ZDNet delivered straight to your inbox

Facebook Activity

White Papers, Webcasts, & Resources
ie8 fix
ie8 fix