Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

SMB:NTLM-LOW-ENTROPY

Severity

High

Recommended

No

Recommended Action

Drop

Category

SMB

Keywords

Microsoft Windows SMB NTLM Authentication Low Entropy

Release Date

2010/10/04

Update Number

1784

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

SMB: Microsoft Windows SMB NTLM Authentication Low Entropy


This signature detects attempts to exploit a known vulnerability in Microsoft Windows SMB. It is due to a lack of cryptographic entropy when generating challenges to authenticate clients. Remote attackers can exploit this by continuously attempting to authenticate against a server. A successful attack can result in arbitrary code execution.

Extended Description

Microsoft Windows is prone to an unauthorized access vulnerability that affects the Microsoft Server Message Block (SMB) protocol software. An unauthenticated attacker can exploit this issue to gain access to resources with the privileges of an authorized user, which may lead to other attacks.

Affected Products

  • Microsoft Windows 2000 Advanced Server SP4
  • Microsoft Windows 2000 Datacenter Server SP4
  • Microsoft Windows 2000 Professional SP4
  • Microsoft Windows 2000 Server SP4
  • Microsoft Windows 7 for 32-bit Systems
  • Microsoft Windows 7 for x64-based Systems
  • Microsoft Windows NT 4.0 SP1
  • Microsoft Windows Server 2003 SP2
  • Microsoft Windows Server 2003 Itanium SP2
  • Microsoft Windows Server 2003 x64 SP2
  • Microsoft Windows Server 2008 for 32-bit Systems SP2
  • Microsoft Windows Server 2008 for 32-bit Systems
  • Microsoft Windows Server 2008 for Itanium-based Systems R2
  • Microsoft Windows Server 2008 for Itanium-based Systems SP2
  • Microsoft Windows Server 2008 for Itanium-based Systems
  • Microsoft Windows Server 2008 for x64-based Systems R2
  • Microsoft Windows Server 2008 for x64-based Systems SP2
  • Microsoft Windows Server 2008 for x64-based Systems
  • Microsoft Windows Vista Business SP1
  • Microsoft Windows Vista Business SP2
  • Microsoft Windows Vista Enterprise SP1
  • Microsoft Windows Vista Enterprise SP2
  • Microsoft Windows Vista Home Basic SP1
  • Microsoft Windows Vista Home Basic SP2
  • Microsoft Windows Vista Home Premium SP1
  • Microsoft Windows Vista Home Premium SP2
  • Microsoft Windows Vista Ultimate SP1
  • Microsoft Windows Vista Ultimate SP2
  • Microsoft Windows Vista x64 Edition SP1
  • Microsoft Windows Vista x64 Edition SP2
  • Microsoft Windows Vista x64 Edition
  • Microsoft Windows XP Home SP2
  • Microsoft Windows XP Home SP3
  • Microsoft Windows XP Media Center Edition SP2
  • Microsoft Windows XP Media Center Edition SP3
  • Microsoft Windows XP Professional SP2
  • Microsoft Windows XP Professional SP3
  • Microsoft Windows XP Professional x64 Edition SP2
  • Microsoft Windows XP Tablet PC Edition SP2
  • Microsoft Windows XP Tablet PC Edition SP3

References

  • BugTraq: 38085
  • CVE: CVE-2010-0231

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out