漏洞信息详情
Microsoft Windows 2000/XP RPC服务远程拒绝服务攻击漏洞(MS03-010)
- CNNVD编号:CNNVD-200304-002
- 危害等级: 中危
- CVE编号:
CVE-2002-1561
- 漏洞类型:
其他
- 发布时间:
2002-10-18
- 威胁类型:
远程
- 更新时间:
2019-05-05
- 厂 商:
microsoft - 漏洞来源:
Dave Aitel※ dave@i… -
漏洞简介
Microsoft Windows 2000/XP是微软公司开发的WINDOWS操作系统。Microsoft Windows 2000/XP的RPC服务存在漏洞,远程攻击者可以利用这个漏洞进行拒绝服务攻击。漏洞存在于Windows系统的DCE-RPC堆栈实现中,远程攻击者可以连接TCP 135端口,发送畸形数据,可导致关闭RPC服务,关闭RPC服务可以引起系统停止对新的RPC请求进行响应,产生拒绝服务。由于众多服务都依赖于RPC服务, 这可能使系统变得不稳定, 很多正常操作无法进行. 例如, Word中将无法使用拷贝/粘贴功能. 根据系统安装的补丁情况, 可能导致Windows XP系统重新起动.
漏洞公告
临时解决方法:
如果您不能立刻安装补丁或者升级,CNNVD建议您采取以下措施以降低威胁:
* 使用防火墙或Windows系统自带的TCP/IP过滤机制对TCP 135端口进行限制,限制外部不可信主机的连接。
厂商补丁:
Microsoft
———
Microsoft已经为此发布了一个安全公告(MS03-010)以及相应补丁:
MS03-010:Flaw in RPC Endpoint Mapper Could Allow Denial of Service Attacks (331953)
链接:
http://www.microsoft.com/technet/security/bulletin/MS03-010.asp” target=”_blank”>
http://www.microsoft.com/technet/security/bulletin/MS03-010.asp
补丁下载:
+ Microsoft Windows 2000
o All except Japanese NEC
http://microsoft.com/downloads/details.aspx?FamilyId=BD55EB38-A5DE-4810-90F7-097C5B4B9919&displaylang=en” target=”_blank”>
http://microsoft.com/downloads/details.aspx?FamilyId=BD55EB38-A5DE-4810-90F7-097C5B4B9919&displaylang=en
o Japanese NEC
http://microsoft.com/downloads/details.aspx?FamilyId=3F7DC0DA-A684-43A8-B2E3-1EEDEEDC822C&displaylang=ja” target=”_blank”>
http://microsoft.com/downloads/details.aspx?FamilyId=3F7DC0DA-A684-43A8-B2E3-1EEDEEDC822C&displaylang=ja
+ Windows XP
o 32-bit Edition
http://microsoft.com/downloads/details.aspx?FamilyId=94213569-3258-4439-9AE7-5D86813B4D9E&displaylang=en” target=”_blank”>
http://microsoft.com/downloads/details.aspx?FamilyId=94213569-3258-4439-9AE7-5D86813B4D9E&displaylang=en
o 64-bit edition
http://microsoft.com/downloads/details.aspx?FamilyId=E3FB88CF-FA48-4426-A4F8-D18D8D4D2295&displaylang=en” target=”_blank”>
http://microsoft.com/downloads/details.aspx?FamilyId=E3FB88CF-FA48-4426-A4F8-D18D8D4D2295&displaylang=en
参考网址
来源:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2002-1561※http://www.securityfocus.com/bid/6005※http://www.nsfocus.net/vulndb/3691
链接:无
来源:BUGTRAQ
链接:http://www.securityfocus.com/archive/1/296114/2002-10-14/2002-10-20/0
来源:MS
链接:https://docs.microsoft.com/en-us/security-updates/securitybulletins/2003/ms03-010
来源:CERT-VN
链接:http://www.kb.cert.org/vuls/id/261537
来源:BID
链接:http://www.securityfocus.com/bid/6005
来源:OVAL
链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A59