SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow SecurityAlert Database

Arrow  Topic :

WZCS vulnerabilities


Arrow  SecurityAlert : 46
Arrow  CVE : CVE-2005-4696
Arrow  CVE : CVE-2005-4697
Arrow  SecurityRisk : Low  Security Risk Low  (About)
Arrow  Remote Exploit : No
Arrow  Local Exploit : Yes
Arrow  Exploit Available : No
Arrow  Credit : László Tóth
Arrow  Published : 04.10.2005

Arrow  Affected Software : Windows XP SP2
Windows XP SP2 with http://support.microsoft.com/?id=893357



Arrow  Advisory Content :  

Summary

"The Wireless Zero Configuration system service enables automatic
configuration for IEEE 802.11 wireless adapters for wireless
communication."

There are two closely related vulnerabilities:

* Once the "View Available Wireless Networks" dialogue box is
opened the Pair-wise Master Keys of the WPA pre-shared key
authentication and WEP keys of the given interface can be found in the
memory of the explorer process, even after closing the dialog box.

* The Wireless Zero Configuration Service can be queried by any
user without administrator privilege to get the WEP keys and WPA
Pair-wise Master Keys.

Details

Remote: No
Risk: low
Vulnerable Systems:

* Windows XP SP2

* Windows XP SP2 with http://support.microsoft.com/?id=893357

Immune Systems: No other than SP2 was tested
Published: 04.10.2005

The WZCS has an RPC interface with some callable functions.
RpcQueryInterface allows local users to get certain data about a
wireless interface, for example the SSID/key pairs. The WEP keys are
in clear text. The WPA pre-shared key is not disclosed, but the PMK is
enough to connect to a wireless network (e.g. you can use
http://hostap.epitest.fi/wpa_supplicant/ which accepts the PMK as an
authentication data).

I found this vulnerability when I realised that if the "View Available
Wireless Networks" is open, the WPA PMKs and WEP keys can be found in
the memory of the explorer process. The dialog is implemented in
wzcdlg.dll that uses wzcsapi.dll which implements WZCQueryInterface.
If you call the WZQueryInterface with the right parameters you can get
the desired information.

Wzcsapi.dll is not documented in Windows XP. However, you can find
some information in the Windows CE documentation. With some debugging
and the help of the aforementioned documentation writing an exploit
code is not a difficult task.

The vulnerabilities were found and the advisory was published by
László Tóth (donctl at gmail dot com).

Special thanks goes to Lajos Antal and Balázs Boda.

History:
Vulnerabilities were discovered in March, 2005.
Vendor was notified 20th March, 2005.
The vendor stated the vulnerabilities as low security issues. They
said you need "debug program" privilege to access this information (I
tested it, you do not need). Therefore they wrote the following:
"At this point, we are looking at possibly shipping a fix for this
issue in a Service Pack, although, there is a strong likelihood that
we will be looking to addressing the issue in the next version of the
product."
Vendor released a feature enhancement patch
(http://support.microsoft.com/?id=893357) that is not related to
these issues.
Vendor was notified 9th May, 2005 that the feature enhancement did not
change the behaviour of the WZCS service regarding the
vulnerabilities.
The Vendor stated they did not intend to fix the vulnerabilities with
this patch and they wrote:
"We feel that the most appropriate ship vehicle for this issue is the
next version of the product which is Longhorn in this case."
At this point the decision was made to publish this advisory.

For more information please visit
http://www.soonerorlater.hu/index.khtml?article_id=62.





Arrow  Feedback :

If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
Alert

libc/fnmatch(3) DoS

Security Risk Medium- 2011-05-13

Allow attacker to denial of service apache 2.2.17 server

Apache RSS Apache Alert

» Apache HTTP Server Denial
   of Service Vulnerability

» Multiple Vendors
   libc/fnmatch(3) DoS (incl
   apache poc)

» Apache Continuum
   cross-site scripting
   vulnerability

» Apache Tomcat DoS
   Vulnerability

PHP RSS PHP Alert

» PHP Hashtables Denial of
   Service

» PHP 5.3.6 multiple null
   pointer dereference

» PHP 5.3.6 ZipArchive
   invalid use glob(3)

» libzip 0.9.3
   _zip_name_locate NULL
   Pointer Dereference (incl
   PHP 5.3.5)

ADT

Protect your family and valuables with Home Security Systems

Copyright © SecurityReason.com. All Rights Reserved.