Short Name |
APP:PPTP:MICROSOFT-PPTP |
---|---|
Severity |
Critical |
Recommended |
No |
Recommended Action |
Drop |
Category |
APP |
Keywords |
Microsoft PPTP DoS |
Release Date |
2005/02/25 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+ |
This signature detects attempts to exploit a known vulnerability against Microsoft Point to Point Tunneling Protocol (PPTP). All versions of Microsoft Windows with PPTP server or PPTP client enabled are vulnerable. Attackers can crash the target kernel or execute arbitrary code.
A buffer overflow vulnerability has been reported for Microsoft's PPTP (Point to Point Tunneling Protocol) implementation. The vulnerability reportedly exists in both the PPTP server and client applications. It is possible for a malicious attacker to craft a packet which causes memory to be corrupted with attacker-supplied data and send it to the PPTP process. This may result in the execution of attacker-supplied malicious code.