Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

SMB:FILE:DLL-TRANSFER

Severity

High

Recommended

No

Recommended Action

Drop

Category

SMB

Keywords

DLL File Transfer

Release Date

2010/09/02

Update Number

1765

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

SMB: DLL File Transfer


This signature detects Microsoft Windows Dynamically Link Libraries (DLL's) transferred via the Server Message Block (SMB) protocol. Vulnerabilities in Microsoft Windows allow an attacker to reference a malicious remote DLL file (using an SMB URI) through a Web page that when the page is accessed overwrites a local DLL, resulting in arbitrary code execution.

Extended Description

Microsoft Windows is prone to an arbitrary-code-execution vulnerability that affects the Data Access Component. Attackers can exploit this vulnerability to execute arbitrary code in the context of the user running the vulnerable application.

Affected Products

  • Avaya Aura Conferencing 6.0.0 Standard
  • Avaya CallPilot 4.0
  • Avaya CallPilot 5.0
  • Avaya Communication Server 1000 Telephony Manager 3.0
  • Avaya Communication Server 1000 Telephony Manager 4.0
  • Avaya Meeting Exchange - Client Registration Server
  • Avaya Meeting Exchange - Recording Server
  • Avaya Meeting Exchange - Streaming Server
  • Avaya Meeting Exchange - Web Conferencing Server
  • Avaya Meeting Exchange - Webportal
  • Avaya Messaging Application Server 4
  • Avaya Messaging Application Server 5.2
  • Microsoft Windows 7 for 32-bit Systems SP1
  • Microsoft Windows 7 for 32-bit Systems
  • Microsoft Windows 7 for Itanium-based Systems SP1
  • Microsoft Windows 7 for Itanium-based Systems
  • Microsoft Windows 7 for x64-based Systems SP1
  • Microsoft Windows 7 for x64-based Systems
  • Microsoft Windows Server 2008 R2
  • Microsoft Windows Server 2008 SP2 Beta
  • Microsoft Windows Server 2008 - Sp2 Enterprise X64
  • Microsoft Windows Server 2008 Datacenter Edition Release Candidate
  • Microsoft Windows Server 2008 Datacenter Edition SP2
  • Microsoft Windows Server 2008 Datacenter Edition
  • Microsoft Windows Server 2008 Enterprise Edition Release Candidate
  • Microsoft Windows Server 2008 Enterprise Edition SP2
  • Microsoft Windows Server 2008 Enterprise Edition
  • Microsoft Windows Server 2008 for 32-bit Systems SP2
  • Microsoft Windows Server 2008 for 32-bit Systems
  • Microsoft Windows Server 2008 for Itanium-based Systems R2
  • Microsoft Windows Server 2008 for Itanium-based Systems SP2
  • Microsoft Windows Server 2008 for Itanium-based Systems
  • Microsoft Windows Server 2008 for x64-based Systems R2
  • Microsoft Windows Server 2008 for x64-based Systems SP2
  • Microsoft Windows Server 2008 for x64-based Systems
  • Microsoft Windows Server 2008 R2 Datacenter SP1
  • Microsoft Windows Server 2008 R2 Datacenter
  • Microsoft Windows Server 2008 R2 Enterprise Edition
  • Microsoft Windows Server 2008 R2 for x64-based Systems SP1
  • Microsoft Windows Server 2008 R2 Itanium SP1
  • Microsoft Windows Server 2008 R2 Itanium
  • Microsoft Windows Server 2008 R2 Standard Edition
  • Microsoft Windows Server 2008 R2 x64 SP1
  • Microsoft Windows Server 2008 R2 x64
  • Microsoft Windows Server 2008 Standard Edition - Gold
  • Microsoft Windows Server 2008 Standard Edition - Gold Datacenter
  • Microsoft Windows Server 2008 Standard Edition - Gold Enterprise
  • Microsoft Windows Server 2008 Standard Edition - Gold Hpc
  • Microsoft Windows Server 2008 Standard Edition - Gold Itanium
  • Microsoft Windows Server 2008 Standard Edition - Gold Standard
  • Microsoft Windows Server 2008 Standard Edition - Gold Storage
  • Microsoft Windows Server 2008 Standard Edition - Gold Web
  • Microsoft Windows Server 2008 Standard Edition Itanium
  • Microsoft Windows Server 2008 Standard Edition R2
  • Microsoft Windows Server 2008 Standard Edition R2 SP1
  • Microsoft Windows Server 2008 Standard Edition Release Candidate
  • Microsoft Windows Server 2008 Standard Edition SP2
  • Microsoft Windows Server 2008 Standard Edition - Sp2 Hpc
  • Microsoft Windows Server 2008 Standard Edition - Sp2 Storage
  • Microsoft Windows Server 2008 Standard Edition - Sp2 Web
  • Microsoft Windows Server 2008 Standard Edition X64
  • Microsoft Windows Server 2008 Standard Edition

References

  • BugTraq: 46678
  • BugTraq: 49353
  • BugTraq: 49026
  • BugTraq: 52036
  • BugTraq: 56354
  • BugTraq: 62836
  • BugTraq: 52375
  • BugTraq: 53011
  • BugTraq: 65745
  • BugTraq: 42695
  • BugTraq: 42654
  • BugTraq: 42628
  • CVE: CVE-2011-0032
  • CVE: CVE-2011-3190
  • CVE: CVE-2011-1975
  • CVE: CVE-2011-2009
  • CVE: CVE-2011-1247
  • CVE: CVE-2011-2980
  • CVE: CVE-2011-2016
  • CVE: CVE-2011-3396
  • CVE: CVE-2011-3396
  • CVE: CVE-2010-3138
  • CVE: CVE-2010-5082
  • CVE: CVE-2012-0756
  • CVE: CVE-2012-0016
  • CVE: CVE-2012-0008
  • CVE: CVE-2012-1241
  • CVE: CVE-2012-1849
  • CVE: CVE-2012-1854
  • CVE: CVE-2012-2519
  • CVE: CVE-2011-1980
  • CVE: CVE-2014-1756
  • CVE: CVE-2011-1991
  • CVE: CVE-2014-0818
  • CVE: CVE-2010-3146
  • CVE: CVE-2013-3485
  • CVE: CVE-2013-0733
  • CVE: CVE-2013-0742
  • CVE: CVE-2010-3131
  • CVE: CVE-2010-3337
  • CVE: CVE-2011-0108
  • CVE: CVE-2011-0029
  • URL: https://www.microsoft.com/technet/security/advisory/2269637.mspx

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out