Korean
<< Back
VID 12042
Severity 40
Port 80, ...
Protocol TCP
Class WWW
Detailed Description Microsoft IIS 5.0 WebDAV service is vulnerable to a buffer overflow attack.
Web Distributed Authoring and Versioning (WebDAV) is an extension to the HTTP 1.1 protocol designed to add distributed authoring and version control to Web content (RFC2518). IIS 5.0 is installed and running on Microsoft Windows 2000 systems and has WebDAV enabled by default. The vulnerability in this WebDAV may allow a remote attacker to run arbitrary code on the victim machine.
A buffer overflow vulnerability exists in ntdll.dll (a portion of code utilized by the IIS WebDAV component). By sending a specially crafted request to an IIS 5.0 server, an attacker may be able to execute arbitrary code in the Local System security context, essentially giving the attacker compete control of the system.

* References:
http://www.cert.org/advisories/CA-2003-09.html
http://www.iss.net/issEn/delivery/xforce/alertdetail.jsp?oid=22029
http://www.microsoft.com/technet/security/bulletin/ms03-007.asp
http://support.microsoft.com/default.aspx?kbid=241520

* Platforms Affected:
Microsoft IIS 5.0
Windows 2000 Any version
Recommendation If use of IIS WebDAV is required, apply the appropriate patch for your system, as listed in Microsoft Security Bulletin MS03-007:
http://microsoft.com/downloads/details.aspx?FamilyId=C9A38D45-5145-4844-B62E-C69D32AC929B&displaylang=en

-- OR --

If use of WebDAV is not required, disable it from the system. To disable WebDAV:

1. Use the IIS lockdown tool. This tool is available here:
http://www.microsoft.com/downloads/release.asp?ReleaseID=43955

2. Alternatively, you can disable WebDAV by following the instructions located in Microsoft's Knowledgebase Article 241520, "How to Disable WebDAV for IIS 5.0":
http://support.microsoft.com/default.aspx?scid=kb;en-us;241520

To completely disable WebDAV including the PUT and DELETE requests, make the following changes in the registry.

1) Start Registry Editor (Regedt32.exe).
2) Locate and click the following key in the registry:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\W3SVC\Parameters

3) On the Edit menu, click Add Value, and then add the following registry value:
Value name: DisableWebDAV
Data type: DWORD
Value data: 1

3. You may also wish to use URLScan, which can block requests for 'PROPFIND' method. Information about URLScan is available at:
http://support.microsoft.com/default.aspx?scid=kb;[LN];326444

-- OR --

If you cannot use either IIS lockdown tool or URLScan, consider restricting the size of the buffer IIS utilizes to process requests by using Microsoft's URL Buffer Size Registry Tool. This tool can be run against a local or remote Windows 2000 system running Windows 2000 Service Pack 2 or Service Pack 3. The tool, instructions on how to use it, and instructions on how to manually make changes to the registry are available here:

URL Buffer Size Registry Tool - http://go.microsoft.com/fwlink/?LinkId=14875
Microsoft Knowledge Base Article 816930 - http://support.microsoft.com/default.aspx?scid=kb;en-us;816930
Microsoft Knowledge Base Article 260694 - http://support.microsoft.com/default.aspx?scid=kb;en-us;260694
Related URL CVE-2003-0109 (CVE)
Related URL 7116 (SecurityFocus)
Related URL 11533 (ISS)