Computer Forums

Member Login

Remember Me? Sign Up! | Forgot Password
 
Slogan
 
Computer Forums > PC Technology Zone > Windows Operating Systems and Software » Apparent IP routing vulnerability affects Vista, not XP
Closed Thread
Old 11-24-2008, 02:39 PM   #1 (permalink)
Mak213's Avatar
 

Join Date: Sep 2004

Location: C:\Windows\System32

Posts: 25,661

Mak213 is a name known to allMak213 is a name known to allMak213 is a name known to allMak213 is a name known to allMak213 is a name known to allMak213 is a name known to all

Default Apparent IP routing vulnerability affects Vista, not XP

A change in the way the Windows client enables IP routes to be amended manually is the target of a potentially serious exploit for Vista users only, that Microsoft may now have no choice but to address.

Through SecurityFocus.com last Wednesday, a team of researchers at Phion published a proof of concept that demonstrates how Microsoft's Internet Protocol Helper API could be exploited to trigger a stack buffer overflow, potentially leading to the execution of random code. Unusually, this particular exploit can only be recreated, Phion said in its bulletin, on Windows Vista Enterprise and Ultimate versions, in 32- and 64-bit editions.

The Phion bulletin explicitly says that Windows XP, which also utilizes this API library, is not affected by this problem. The library in question has been in existence since Windows NT 4.0 Service Pack 4, and has been a regular component of successive versions since Windows 98.

Windows Vista was the first client operating system from Microsoft to support IPv6 protocol as a standard feature, although IPv6 remains an option for XP and older clients. It's that distinction which leads to the Vista-specificity of this issue. The IP Helper API gives developers more direct access to the functions necessary for a Windows computer to utilize IP. So naturally, one of the functions included enables a program to establish an IP route for the local computer, and the original form of that function was called CreateIpForwardEntry.

Since the introduction of IPv6 as standard issue, the library had to offer an alternative way to phrase the forward route entry, though it had to also leave the earlier version of the function for backward compatibility. Thus the creation of CreateIpForwardEntry2, an API function that is only workable in Vista. An XP or older client would never make use of it, presumably even with IPv6 intentionally installed.

Thus the situation where the route add command, as Phion illustrated, can be gamed in such a way that it triggers a buffer overflow in Vista but not in XP. Evidently the command utilizes the older API function in XP, and the newer one in Vista.

Source
__________________
R.I.P. Danny L. Trotter
14 Nov 1945 - 4 Sept 2009
Images created by CarnageX | Decaptured...Listen! | Visit Baezware!! | You've been Mak'd! | 儿做好
I do not accept support questions via EMail, PM, IM or my Spaces page! .:|:. This is what happens when an unstoppable force meets an immovable object.
Thanks to all the guys on the staff for your support in my time of need. Hefe you are my personal Hero for your contribution.



<<<< If I help you, or you just like what I said, rep me
Mak213 is offline  
 
Closed Thread

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Can't network (ping) between vista and win2003, all other's ok PolishPaul Computer Networking & Internet Access 5 10-05-2008 08:01 AM
Buying a Vista Laptop cyclones Everything Laptops 23 08-01-2008 04:32 PM
Windows Vista SP1 Download Osiris Windows Operating Systems and Software 42 03-22-2008 04:23 AM
hasta la VISTA..baby! nu2duo Windows Operating Systems and Software 30 03-19-2008 10:41 PM
soundcard for vista = worthless? macdawg Building, Buying, or Upgrading High Performance PC Systems 34 05-05-2007 10:56 PM