English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 26160
À§Çèµµ 30
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®´Â MSRPC SVCCTL ¼­ºñ½º ¿­°Å Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Microsoft Windows NT 4.0 ±×¸®°í Windows 2000 SP4¸¦ À§ÇÑ URP1ÀÌ ¼³Ä¡µÇÁö ¾ÊÀº Windows 2000Àº NULL ¼¼¼ÇµéÀ» ÅëÇØ ¶Ç ´Ù¸¥ ´ëü °¡´ÉÇÑ Named Pipeµé(svcctl ´ë½Å¿¡ srvsvc)À» ¾×¼¼½ºÇÏÁö ¸øÇÏ°Ô ÀûÀýÇÏ°Ô Â÷´ÜÇÏÁö ¸øÇÏ¿© ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ¿µÇâÀ» ¹Þ´Â ÄÄÇ»ÅÍÀÇ ¼­ºñ½ºµéÀÌ ¼³Ä¡µÇ¾î ÀÖ´ÂÁö ȤÀº °¡µ¿ ÁßÀÎÁö¸¦ ¿­°ÅÇØ º¼ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â svcctl Microsoft RPC ÀÎÅÍÆäÀ̽º¸¦ È£ÃâÇÏ¿© ¼­ºñ½º Á¦¾î °ü¸®ÀÚ(Service Control Manager)¿¡ Á¢¼ÓÇÑ ÈÄ ´ë»ó ½Ã½ºÅÛ »ó¿¡ ¾î¶² ¼­ºñ½ºµéÀÌ ¼³Ä¡µÇ¾î ÀÖ°í °¡µ¿ ÁßÀÎÁö¸¦ ¾Ë ¼ö ÀÖ´Ù. ¶ÇÇÑ ÀÌ °áÇÔÀ» µµ¿ëÇÔÀ¸·Î½á Windows ¼­ºñ½ºµéÀ» ½ÃÀÛÇϰųª ÁßÁöÇÒ ¼öµµ ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://support.microsoft.com/kb/891861
http://www.hsc.fr/ressources/presentations/null_sessions/msrpc_null_sessions.pdf
http://support.microsoft.com/kb/842209
http://www.securitytracker.com/alerts/2005/Jul/1014417.html
http://securityfocus.com/archive/1/404547

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Windows NT 4.0 SP6a
Microsoft Windows 2000 SP4
ÇØ°áÃ¥ Microsoft Windows 2000ÀÇ °æ¿ì:
´ÙÀ½ 'Microsoft Knowledge Base Article - 891861' À» ÂüÁ¶ÇÏ¿© Update Rollup Package 1 (KB891861)À» ¼³Ä¡ÇÑ´Ù:
http://support.microsoft.com/kb/891861

-- ¶Ç´Â --

Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î´Â, ´ÙÀ½ Microsoft Knowledge Base Article 842209¸¦ ÂüÁ¶ÇÏ¿© ƯÁ¤ ·¹Áö½ºÆ®¸® ¿£Æ®¸®µé°ú ±¸¼º ¿É¼ÇµéÀ» ¼öÁ¤ÇÏ¿©¾ß ÇÑ´Ù:
http://support.microsoft.com/kb/842209
°ü·Ã URL CVE-2005-2150 (CVE)
°ü·Ã URL 14093,14177 (SecurityFocus)
°ü·Ã URL 21286 (ISS)