August 09, 2011
Microsoft Security Bulletin: August 9
Advisory Overview

August 9, 2011 - Qualys® Vulnerability R&D Lab has released new vulnerability checks in QualysGuard® to protect organizations against 13 vulnerabilities present in Microsoft Windows that were announced today. Customers can immediately audit their networks for these and other new vulnerabilities by accessing their QualysGuard subscription.

Vulnerability Details

Microsoft has released 13 security patches to fix newly discovered flaws in Microsoft Windows. Qualys has released the following checks for these new vulnerabilities:


Microsoft Internet Explorer Cumulative Security Update (MS11-057)
SEVERITY: Urgent Urgent-5 5
QUALYS ID: 100105
VENDOR REFERENCE: MS11-057
CVE REFERENCE: CVE-2011-1257 | CVE-2011-2383 | CVE-2011-1960 | CVE-2011-1961 | CVE-2011-1962 | CVE-2011-1963 | CVE-2011-1964
CVSS SCORES: Base 9.3 | Temporal 7.3
THREAT: This security update resolves five privately reported vulnerabilities and two publicly disclosed vulnerabilities in Internet Explorer.

The update addresses the vulnerabilities by modifying the way Internet Explorer handles objects in memory, handles JavaScript event handlers, renders data during certain processes, accesses files stored in the local machine, and manages cookie files; and by modifying the way the telnet handler executes the associated application.

This security update is rated Critical for Internet Explorer 6 on Windows clients, Internet Explorer 7, Internet Explorer 8, and Internet Explorer 9; and Important for Internet Explorer 6 on Windows servers.

IMPACT: An attacker who successfully exploited any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less affected than users who operate with administrative user rights.
SOLUTION: Patch:
Following are links for downloading patches to fix the vulnerabilities:

Windows XP Service Pack 3 (Internet Explorer 6)

Windows XP Professional x64 Edition Service Pack 2 (Internet Explorer 6)

Windows Server 2003 Service Pack 2 (Internet Explorer 6)

Windows Server 2003 x64 Edition Service Pack 2 (Internet Explorer 6)

Windows Server 2003 with SP2 for Itanium-based Systems (Internet Explorer 6)

Windows XP Service Pack 3 (Internet Explorer 7)

Windows XP Professional x64 Edition Service Pack 2 (Internet Explorer 7)

Windows Server 2003 Service Pack 2 (Internet Explorer 7)

Windows Server 2003 x64 Edition Service Pack 2 (Internet Explorer 7)

Windows Server 2003 with SP2 for Itanium-based Systems (Internet Explorer 7)

Windows Vista Service Pack 2 (Internet Explorer 7)

Windows Vista x64 Edition Service Pack 2 (Internet Explorer 7)

Windows Server 2008 for 32-bit Systems Service Pack 2 (Internet Explorer 7)

Windows Server 2008 for x64-based Systems Service Pack 2 (Internet Explorer 7)

Windows XP Professional x64 Edition Service Pack 2 (Internet Explorer 8)

Refer to Microsoft Security Bulletin MS11-057 for further details.

Workaround:
1) Set Internet and Local intranet security zone settings to "High" to prompt before running ActiveX Controls and Active Scripting
2) Configure Internet Explorer to prompt before running Active Scripting or to disable Active Scripting in the Internet and Local intranet security zone

Impact of workaround #1 and #2: You will be prompted frequently when visiting Web sites on the Internet or Intranet that use ActiveX or Active Scripting to provide additional functionality.


Microsoft Windows DNS Server Remote Code Execution Vulnerability (MS11-058)
SEVERITY: Urgent Urgent-5 5
QUALYS ID: 90726
VENDOR REFERENCE: MS11-058
CVE REFERENCE: CVE-2011-1966 | CVE-2011-1970
CVSS SCORES: Base 10 | Temporal 7.4
THREAT: Multiple vulnerabilities exist in Windows DNS server.

A remote code execution vulnerability is caused when a non-authoritative DNS server improperly handles a specially crafted NAPTR record in memory while recursively requesting the record from the authoritative DNS server.

A denial of service vulnerability exists in the way that the DNS server improperly handles an object in memory that has not been initialized.

Microsoft has released a security update that addresses the vulnerabilities by modifying the way that the DNS server handles NAPTR queries in memory and initializes objects in memory before use.

This security update is rated Critical for 32-bit and x64-based editions of Windows Server 2008, and x64-based editions of Windows Server 2008 R2; and Important for all supported editions of Windows Server 2003.

IMPACT: Exploitation could result in remote code execution or cause a denial of service.
SOLUTION: Patch:
Following are links for downloading patches to fix the vulnerabilities:

Windows Server 2003 Service Pack 2

Windows Server 2003 x64 Edition Service Pack 2

Windows Server 2003 with SP2 for Itanium-based Systems

Windows Server 2008 for 32-bit Systems Service Pack 2

Windows Server 2008 for x64-based Systems Service Pack 2

Windows Server 2008 R2 for x64-based Systems and Windows Server 2008 R2 for x64-based Systems Service Pack 1

Refer to Microsoft Security Bulletin MS11-058 for further details.

Workaround:
Disable the DNS service if you are not using it.


Microsoft Data Access Components Remote Code Execution Vulnerability (MS11-059)
SEVERITY: Critical Critical-4 4
QUALYS ID: 90722
VENDOR REFERENCE: MS11-059
CVE REFERENCE: CVE-2011-1975
CVSS SCORES: Base 9.3 | Temporal 6.9
THREAT: Microsoft Data Access Components is a collection of components that make it easy for programs to access databases and then to manipulate the data within them.

A remote code execution vulnerability exists in the way that the Windows Data Access Tracing component handles the loading of DLL files.(CVE-2011-1975).

This security update is rated Important for all supported editions of Windows 7 and Windows Server 2008 R2.

IMPACT: Successfully exploiting this vulnerability might allow a remote attacker to execute arbitrary code.
SOLUTION: Patch:
Following are links for downloading patches to fix the vulnerabilities:

Windows 7 for 32-bit Systems and Windows 7 for 32-bit Systems Service Pack 1

Windows 7 for x64-based Systems and Windows 7 for x64-based Systems Service Pack 1

Windows Server 2008 R2 for x64-based Systems and Windows Server 2008 R2 for x64-based Systems Service Pack 1

Windows Server 2008 R2 for Itanium-based Systems and Windows Server 2008 R2 for Itanium-based Systems Service Pack 1

Refer to Microsoft Security Bulletin MS11-059 for further details.

Workaround:
1) Disable loading of libraries from WebDAV and remote network shares
2) Disable the WebClient service

Impact of workaround #2: When the WebClient service is disabled, Web Distributed Authoring and Versioning (WebDAV) requests are not transmitted. In addition, any services that explicitly depend on the Web Client service will not start, and an error message will be logged in the System log.
3) Block TCP ports 139 and 445 at the firewall

Impact of workaround #3: Several Windows services use the affected ports. Blocking connectivity to the ports may prevent various applications or services from functioning.


Microsoft Office Visio Remote Code Execution Vulnerability (MS11-060)
SEVERITY: Critical Critical-4 4
QUALYS ID: 110156
VENDOR REFERENCE: MS11-060
CVE REFERENCE: CVE-2011-1972 | CVE-2011-1979
CVSS SCORES: Base 7.5 | Temporal 5.5
THREAT: Microsoft Visio is diagramming software for Microsoft Windows. It uses vector graphics to create diverse diagrams.

Two remote code execution vulnerabilities exists due to the application not properly validating objects in memory when parsing crafted Visio files. (CVE-2011-1972, CVE-2011-1979)

Microsoft has released a security update that addresses the vulnerabilities by correcting the way that Microsoft Visio handles corrupted structures and objects in memory when parsing specially crafted Visio files.

The security update is rated Important for all supported editions of Microsoft Visio 2003, Visio 2007 and Visio 2010.

IMPACT: An attacker who successfully exploits this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less affected than users who operate with administrative user rights.
SOLUTION: Patch:
Following are links for downloading patches to fix the vulnerabilities:

Microsoft Visio 2003 Service Pack 3

Microsoft Visio 2007 Service Pack 2

Microsoft Visio 2010 and Microsoft Visio 2010 Service Pack 1 (32-bit editions)

Microsoft Visio 2010 and Microsoft Visio 2010 Service Pack 1 (64-bit editions)

Refer to Microsoft Security Bulletin MS11-060 for further details.

Workaround:
Do not open untrusted Office files


Microsoft Windows Remote Desktop Web Access Elevation of Privilege Vulnerability (MS11-061)
SEVERITY: Critical Critical-4 4
QUALYS ID: 90728
VENDOR REFERENCE: MS11-061
CVE REFERENCE: CVE-2011-1263
CVSS SCORES: Base 5.8 | Temporal 4.3
THREAT: Remote Desktop Web Access (RD Web Access) is a role service in the Remote Desktop Services role that lets you make RemoteApp programs, virtual desktops, and session-based desktops available to users by using a Web browser.

A reflected XSS vulnerability is caused when the logon page for Remote Desktop Web Access improperly validates a URL parameter.

Microsoft has released a security update to addresses the vulnerability by correcting the manner in which the logon page for Remote Desktop Web Access validates input parameters.

This security update is rated Important for all supported editions of Windows Server 2008 R2.

IMPACT: An attacker who successfully exploits this vulnerability could inject a client-side script into the user's instance of Internet Explorer. The script could spoof content, disclose information, or take any action that the user could take on the Remote Desktop Web Access site.
SOLUTION: Patch:
Following are links for downloading patches to fix the vulnerabilities:

Windows Server 2008 R2 for x64-based Systems and Windows Server 2008 R2 for x64-based Systems Service Pack 1

Refer to Microsoft Security Bulletin MS11-061 for further details.

Workaround:
1) Enable Internet Explorer 8 and Internet Explorer 9 XSS filter for Intranet Zone

Impact of workaround #1: Internal sites not previously flagged as being XSS risks would be flagged.


Microsoft Remote Access Service NDISTAPI Driver Elevation of Privilege Vulnerability (MS11-062)
SEVERITY: Critical Critical-4 4
QUALYS ID: 90724
VENDOR REFERENCE: MS11-062
CVE REFERENCE: CVE-2011-1974
CVSS SCORES: Base 9.3 | Temporal 6.9
THREAT: Remote Access Service (RAS) lets users connect to a remote computer over the phone lines, the Internet, or other network connection so they can work as if their system were physically connected to the remote network. The NDISTAPI driver is part of the RAS architecture and interfaces the NDISWAN to TAPI services.

An elevation of privilege vulnerability exists in the Remote Access Service NDISTAPI driver. The vulnerability is caused when the NDISTAPI driver improperly validates user-supplied input when passing data from user mode to the Windows kernel. (CVE-2011-1974)

Affected Software:
Windows XP Service Pack 3
Windows XP Professional x64 Edition Service Pack 2
Windows Server 2003 Service Pack 2
Windows Server 2003 x64 Edition Service Pack 2
Windows Server 2003 with SP2 for Itanium-based Systems

IMPACT: An attacker who successfully exploits this vulnerability could run arbitrary code in the context of the local system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
SOLUTION: Patch:
Following are links for downloading patches to fix the vulnerabilities:

Windows XP Service Pack 3

Windows XP Professional x64 Edition Service Pack 2

Windows Server 2003 Service Pack 2

Windows Server 2003 x64 Edition Service Pack 2

Windows Server 2003 with SP2 for Itanium-based Systems

Refer to Microsoft Security Bulletin MS11-062 for further details.


Microsoft Remote Access Service NDISTAPI Driver Elevation of Privilege Vulnerability (MS11-062)
SEVERITY: Critical Critical-4 4
QUALYS ID: 90724
VENDOR REFERENCE: MS11-062
CVE REFERENCE: CVE-2011-1974
CVSS SCORES: Base 9.3 | Temporal 6.9
THREAT: Remote Access Service (RAS) lets users connect to a remote computer over the phone lines, the Internet, or other network connection so they can work as if their system were physically connected to the remote network. The NDISTAPI driver is part of the RAS architecture and interfaces the NDISWAN to TAPI services.

An elevation of privilege vulnerability exists in the Remote Access Service NDISTAPI driver. The vulnerability is caused when the NDISTAPI driver improperly validates user-supplied input when passing data from user mode to the Windows kernel. (CVE-2011-1974)

Affected Operating System:
> Windows XP Service Pack 3
> Windows XP Professional x64 Edition Service Pack 2
> Windows Server 2003 Service Pack 2
> Windows Server 2003 x64 Edition Service Pack 2
> Windows Server 2003 with SP2 for Itanium-based Systems

IMPACT: An attacker who successfully exploits this vulnerability could run arbitrary code in the context of the local system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.
SOLUTION: Patch:
Following are links for downloading patches to fix the vulnerabilities:

Windows XP Service Pack 3

Windows XP Professional x64 Edition Service Pack 2

Windows Server 2003 Service Pack 2

Windows Server 2003 x64 Edition Service Pack 2

Windows Server 2003 with SP2 for Itanium-based Systems

Refer to Microsoft Security Bulletin MS11-062 for further details.


Microsoft Windows Client/Server Run-time Subsystem Elevation of Privilege Vulnerability (MS11-063)
SEVERITY: Minimal Minimal-1 1
QUALYS ID: 90721
VENDOR REFERENCE: MS11-063
CVE REFERENCE: CVE-2011-1967
CVSS SCORES: Base 7.2 | Temporal 5.6
THREAT: This security update resolves a privately reported vulnerability in Microsoft Windows by modifying the way that the Client/Server Run-time Subsystem (CSRSS) evaluates inter-process device event message permissions.
This security update is rated Important for all supported versions of Microsoft Windows.
IMPACT: The vulnerability could allow elevation of privilege if an attacker logs on to an affected system and runs a specially crafted application designed to send a device event message to a higher-integrity process. An attacker must have valid logon credentials and be able to log on locally to exploit this vulnerability.
SOLUTION: N/A

Microsoft Windows TCP/IP Denial of Service Vulnerability (MS11-064)
SEVERITY: Serious Serious-3 3
QUALYS ID: 90731
VENDOR REFERENCE: MS11-064
CVE REFERENCE: CVE-2011-1871 | CVE-2011-1965
CVSS SCORES: Base 7.8 | Temporal 5.8
THREAT: TCP/IP is a set of networking protocols that are widely used on the Internet. TCP/IP provides communication across interconnected networks of computers that have diverse hardware architectures and that run various operating systems. The following vulnerabilities exist in TCP/IP processing in Windows.

A denial of service vulnerability exists in TCP/IP processing due to improperly processing a sequence of any specially crafted ICMP messages. (CVE-2011-1871)

A denial of service vulnerability exists in the TCP/IP stack, which occurs when the TCP/IP stack improperly handles URLs in memory when URL-based Quality of Service(QoS) is enabled. (CVE-2011-1965)

The security update is rated Important for all supported editions of Microsoft Windows Vista, Windows Server 2008, Windows 7 and Windows Server 2008 R2.

IMPACT: Successfully exploiting this vulnerability might allow a remote attacker to cause a denial of service.
SOLUTION: Patch:
Following are links for downloading patches to fix the vulnerabilities:

Windows Vista Service Pack 2

Windows Vista x64 Edition Service Pack 2

Windows Server 2008 for 32-bit Systems Service Pack 2

Windows Server 2008 for x64-based Systems Service Pack 2

Windows Server 2008 for Itanium-based Systems Service Pack 2

Windows 7 for 32-bit Systems and Windows 7 for 32-bit Systems Service Pack 1

Windows 7 for x64-based Systems and Windows 7 for x64-based Systems Service Pack 1

Windows Server 2008 R2 for x64-based Systems and Windows Server 2008 R2 for x64-based Systems Service Pack 1

Windows Server 2008 R2 for Itanium-based Systems and Windows Server 2008 R2 for Itanium-based Systems Service Pack 1

Refer to Microsoft Security Bulletin MS11-064 for further details.

Workaround:
1) Block ICMP at the firewall

Impact of workaround #1: This workaround can negatively impact performance by preventing TCP from optimizing network communication. ICMP network packets can eliminate fragmentation at routers connecting networks with different MTUs. Fragmentation reduces TCP throughput and increases network congestion.

2) Disable Policy-based QoS.


Microsoft Windows Remote Desktop Protocol Denial of Service Vulnerability (MS11-065)
SEVERITY: Serious Serious-3 3
QUALYS ID: 90723
VENDOR REFERENCE: MS11-065
CVE REFERENCE: CVE-2011-1968
CVSS SCORES: Base 7.8 | Temporal 5.8
THREAT: The Remote Desktop feature in Windows enables access to all of the programs, resources, and accessories on a user's computer from a second Windows-based computer.

A denial of service vulnerability exists in the way the Remote Desktop Protocol accesses an object in memory that has been improperly initialized or has been deleted (CVE-2011-1968).

This security update is rated Important for all supported editions of Windows Server 2003 and Moderate for all supported editions of Windows XP.

IMPACT: Successfully exploiting this vulnerability might allow a remote attacker to cause a denial of service.
SOLUTION: Patch:
Following are links for downloading patches to fix the vulnerabilities:

Windows XP Service Pack 3

Windows XP Professional x64 Edition Service Pack 2

Windows Server 2003 Service Pack 2

Windows Server 2003 x64 Edition Service Pack 2

Windows Server 2003 with SP2 for Itanium-based Systems

Refer to Microsoft Security Bulletin MS11-065 for further details.

Workaround:
1) Disable Terminal Services, Remote Desktop, Remote Assistance, and Windows Small Business Server 2003 Remote Web Workplace feature if no longer required.

2) Block TCP port 3389 at the enterprise perimeter firewall.


Microsoft Chart Control Information Disclosure Vulnerability (MS11-066)
SEVERITY: Serious Serious-3 3
QUALYS ID: 90727
VENDOR REFERENCE: MS11-066
CVE REFERENCE: CVE-2011-1977
CVSS SCORES: Base 7.5 | Temporal 5.5
THREAT: Microsoft Chart controls enable you to create ASP.NET pages or Windows Forms applications with simple, intuitive, and visually compelling charts for complex statistical or financial analysis

An information disclosure vulnerability exists in the way that Microsoft Chart controls incorrectly handle special characters within a specially crafted URI.(CVE-2011-1977).

This security update is rated Important for Microsoft .NET Framework 4 on all supported releases of Microsoft Windows and for Chart Control for Microsoft .NET Framework 3.5 Service Pack 1.

IMPACT: Successfully exploiting this vulnerability might allow a remote attacker to read the contents of any file within the web site directory or subdirectories.
SOLUTION: Patch:
Following are links for downloading patches to fix the vulnerabilities:

Windows XP Service Pack 3 (Microsoft .NET Framework 4)

Windows XP Professional x64 Edition Service Pack 2 (Microsoft .NET Framework 4)

Windows Server 2003 Service Pack 2 (Microsoft .NET Framework 4)

Windows Server 2003 x64 Edition Service Pack 2 (Microsoft .NET Framework 4)

Windows Server 2003 with SP2 for Itanium-based Systems (Microsoft .NET Framework 4)

Windows Vista Service Pack 2 (Microsoft .NET Framework 4)

Windows Vista x64 Edition Service Pack 2 (Microsoft .NET Framework 4)

Windows Server 2008 for 32-bit Systems Service Pack 2 (Microsoft .NET Framework 4)

Windows Server 2008 for x64-based Systems Service Pack 2 (Microsoft .NET Framework 4)

Windows Server 2008 for Itanium-based Systems Service Pack 2 (Microsoft .NET Framework 4)

Windows 7 for 32-bit Systems and Windows 7 for 32-bit Systems Service Pack 1 (Microsoft .NET Framework 4)

Windows 7 for x64-based Systems and Windows 7 for x64-based Systems Service Pack 1 (Microsoft .NET Framework 4)

Windows Server 2008 R2 for x64-based Systems and Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Microsoft .NET Framework 4)

Windows Server 2008 R2 for Itanium-based Systems and Windows Server 2008 R2 for Itanium-based Systems Service Pack 1 (Microsoft .NET Framework 4)

Chart Control for Microsoft .NET Framework 3.5 Service Pack 1

Refer to Microsoft Security Bulletin MS11-066 for further details.


Microsoft Report Viewer Information Disclosure Vulnerability (MS11-067)
SEVERITY: Urgent Urgent-5 5
QUALYS ID: 90725
VENDOR REFERENCE: MS11-067
CVE REFERENCE: CVE-2011-1976
CVSS SCORES: Base 9.3 | Temporal 7.3
THREAT: This security update resolves a privately reported vulnerability in Microsoft Report Viewer by correcting the manner in which the Microsoft Report Viewer control validates parameters within a data source.

This security update is rated Important for all supported editions of Microsoft Visual Studio 2005 and Microsoft Report Viewer 2005 Redistributable Package.

IMPACT: The vulnerability could allow information disclosure if a user views a specially crafted Web page. In all cases, an attacker would have no way to force a user to visit the Web site. Instead, an attacker would have to persuade a user to visit the Web site, typically by getting them to click a link in an email message or Instant Messenger message that takes the user to the vulnerable Web site.
SOLUTION: Patch:
Following are links for downloading patches to fix the vulnerabilities:

Microsoft Visual Studio 2005 Service Pack 1

Microsoft Report Viewer 2005 Service Pack 1 Redistributable Package

Refer to Microsoft Security Bulletin MS11-067 for further details.

Workaround:
1) Set Internet and Local intranet security zone settings to "High" to prompt before running ActiveX Controls and Active Scripting

2) Configure Internet Explorer to prompt before running Active Scripting or to disable Active Scripting in the Internet and Local intranet security zone

Impact of workaround #1 and #2:
On visiting Web sites on the Internet or Intranet that use ActiveX or Active Scripting to provide additional functionality, you will be prompted frequently when you enable this workaround.


Microsoft Windows Kernel Denial of Service Vulnerability (MS11-068)
SEVERITY: Critical Critical-4 4
QUALYS ID: 90730
VENDOR REFERENCE: MS11-068
CVE REFERENCE: CVE-2011-1971
CVSS SCORES: Base 7.8 | Temporal 5.8
THREAT: The Windows kernel is the core of the operating system. The kernel provides system-level services such as device management and memory management, allocates processor time to processes, and manages error handling.

A denial of service vulnerability is caused when the Windows kernel improperly parses metadata information in files.

Microsoft has released a security update that addresses the vulnerability by correcting the way that the Windows kernel parses metadata information in files.

This security update is rated Moderate for all supported editions of Windows Vista, Windows Server 2008, Windows 7, and Windows Server 2008 R2.

IMPACT: An attacker who successfully exploits this vulnerability could cause the affected system to restart.
SOLUTION: Patch:
Following are links for downloading patches to fix the vulnerabilities:

Windows Vista Service Pack 2

Windows Vista x64 Edition Service Pack 2

Windows Server 2008 for 32-bit Systems Service Pack 2

Windows Server 2008 for x64-based Systems Service Pack 2

Windows Server 2008 for Itanium-based Systems Service Pack 2

Windows 7 for 32-bit Systems

Windows 7 for 32-bit Systems Service Pack 1

Windows 7 for x64-based Systems

Windows 7 for x64-based Systems Service Pack 1

Windows Server 2008 R2 for x64-based Systems

Windows Server 2008 R2 for x64-based Systems Service Pack 1

Windows Server 2008 R2 for Itanium-based Systems

Windows Server 2008 R2 for Itanium-based Systems Service Pack 1

Refer to Microsoft Security Bulletin MS11-068 for further details.

Workaround:
1) Disable the WebClient service

Impact of workaround #1: When the WebClient service is disabled, Web Distributed Authoring and Versioning (WebDAV) requests are not transmitted. In addition, any services that explicitly depend on the Web Client service will not start, and an error message will be logged in the System log.

2) Disable the Preview Pane and Details Pane in Windows Explorer

Impact of workaround #2: Windows Explorer will not automatically display OTF fonts.

3) Block TCP ports 139 and 445 at the firewall

Impact of workaround #3: Several Windows services use the affected ports. Blocking connectivity to the ports may cause various applications or services to not function.


Microsoft .NET Framework Information Disclosure Vulnerability (MS11-069)
SEVERITY: Critical Critical-4 4
QUALYS ID: 90729
VENDOR REFERENCE: MS11-069
CVE REFERENCE: CVE-2011-1978
CVSS SCORES: Base 6.8 | Temporal 5
THREAT: The System.Net.Sockets namespace within the .NET Framework provides a managed implementation of the Windows Sockets (Winsock) interface for developers who need to tightly control access to the network.

An information disclosure vulnerability exists in the way that .NET Framework improperly validates the trust level within the System.Net.Sockets namespace. (CVE-2011-1978)

Affected Software:
Windows XP Service Pack 3 (Microsoft .NET Framework 2.0 Service Pack 2 and Microsoft .NET Framework 4)
Windows XP Professional x64 Edition Service Pack 2 (Microsoft .NET Framework 2.0 Service Pack 2 and Microsoft .NET Framework 4)
Windows Server 2003 Service Pack 2 (Microsoft .NET Framework 2.0 Service Pack 2 and Microsoft .NET Framework 4)
Windows Server 2003 x64 Edition Service Pack 2 (Microsoft .NET Framework 2.0 Service Pack 2 and Microsoft .NET Framework 4)

IMPACT: An attacker who successfully exploited this vulnerability would be able to access information not intended to be exposed. Additionally, this vulnerability could be used by an attacker to direct network traffic from a victim's system to other network resources the victim can access. This could allow an attacker to perform a denial of service to any system the victim's system can access or use the victim's system to perform scanning of network resources available to the victim.
SOLUTION: N/A

This new vulnerability check is included in Qualys vulnerability signatures 1.28.183-4. Each QualysGuard account is automatically updated with the latest vulnerability signatures as they become available. To view the vulnerability signature version in your account, from the QualysGuard HOME menu, select the Account Info tab.

SELECTIVE SCAN INSTRUCTIONS USING QUALYSGUARD:

To perform a selective vulnerability scan, configure a scan profile to use the following options:

  1. Ensure access to TCP ports 135 and 139 are available.
  2. Enable Windows Authentication (specify Authentication Records).
  3. Enable the following Qualys IDs:
    • 100105
    • 90726
    • 90722
    • 110156
    • 90728
    • 90724
    • 90721
    • 90731
    • 90723
    • 90727
    • 90725
    • 90730
    • 90729
  4. If you would like the scan to return the Windows Hostname, also include QID 82044 and ensure access to UDP port 137 is available.
  5. If you would like to be notified if QualysGuard is unable to logon to a host (if Authentication fails), also include QID 105015.

In addition, prior to running a scan for these new vulnerabilities, you can estimate your exposure to these new threats by running the Risk Matrix Report, available from the QualysGuard HOME page.


Technical Support
For more information, customers may contact Qualys Technical Support directly at support@qualys.com or by telephone toll free at:
US: 1 866.801.6161 | EMEA: 33 1 44.17.00.41 | UK: +44 1753 872102
About QualysGuard
QualysGuard is an on-demand security audit service delivered over the web that enables organizations to effectively manage their vulnerabilities and maintain control over their network security with centralized reports, verified remedies, and full remediation workflow capabilities with trouble tickets. QualysGuard provides comprehensive reports on vulnerabilities including severity levels, time to fix estimates and impact on business, plus trend analysis on security issues. By continuously and proactively monitoring all network access points, QualysGuard dramatically reduces security managers' time researching, scanning and fixing network exposures and enables companies to eliminate network vulnerabilities before they can be exploited.

Access for QualysGuard customers: https://qualysguard.qualys.com

Free trial of QualysGuard service: http://www.qualys.com/forms/trials/qualysguard_trial/