Lucene search

K
certCERTVU:149070
HistoryJun 05, 2012 - 12:00 a.m.

Symantec Endpoint Protection network threat protection module Microsoft IIS denial of service vulnerability

2012-06-0500:00:00
www.kb.cert.org
17

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.01

Percentile

83.5%

Overview

Symantec Endpoint Protection (SEP) Network Threat Protection module running on a Microsoft Internet Information Services (IIS) webserver contains a denial of service vulnerability when probed by an audit tool.

Description

Symantec Security Advisory SYM12-007 states:

Overview
Versions of Symantec Endpoint Protection Manager 11.0 running the Network Threat Protection module on Windows Server 2003 are susceptible to a Denial of Service(DoS). Successful exploitation could potentially result in the system hosting Symantec Endpoint Protection Manager becoming unresponsive to IIS-based web server requests until restarted.

_Details
Symantec was notified of a Denial of Service(DoS) within the Symantec Endpoint Protection Manager 11 RU6 and related maintenance packs.

A successful exploitation is possible when using audit tools to aggressively scan the targeted Symantec Endpoint Protection Manager host. After a period of heavy scanning the Network Threat Protection module responds to the perceived threat by blocking all subsequent traffic to the server. This can lead the server to stop serving pages and in some instances can cause excessive resource use which can lead to a hang or crash of the server.

This issue does not impact the security of the Symantec Endpoint Manager, only the availability of the web server components._

It has been reported that this vulnerability affects Microsoft Internet Information Services (IIS) 6.0, however newer versions could be affected.


Impact

An unauthenticated attacker can cause the Microsoft IIS webserver to become unresponsive leading to a denial of service condition.


Solution

Update

The vendor has stated that this vulnerability has been addressed in SEP 11.0.7000 RU7 MP2. Users are advised to upgrade to release SEP 11.0.7000 RU7 MP2 or later. The vendor states that updates will be available through customers’ normal support/download locations.


Restart server or IIS service

The vendor has stated that manually restarting the server and/or IIS service will remedy the situation.


Vendor Information

149070

Filter by status: All Affected Not Affected Unknown

Filter by content: __ Additional information available

__ Sort by: Status Alphabetical

Expand all

Javascript is disabled. Click here to view vendors.

Symantec Affected

Notified: May 12, 2011 Updated: May 22, 2012

Status

Affected

Vendor Statement

We have not received a statement from the vendor.

Vendor Information

We are not aware of further vendor information regarding this vulnerability.

Vendor References

CVSS Metrics

Group Score Vector
Base 4.3 AV:N/AC:M/Au:N/C:N/I:N/A:P
Temporal 3.2 E:U/RL:OF/RC:C
Environmental 1 CDP:L/TD:L/CR:ND/IR:ND/AR:ND

References

http://www.symantec.com/security_response/securityupdates/detail.jsp?fid=security_advisory&pvid=security_advisory&year=2012&suid=20120522_00

Acknowledgements

Thanks to Greg Johnson of Clear Skies Security for reporting this vulnerability.

This document was written by Michael Orlando.

Other Information

CVE IDs: CVE-2012-1821
Date Public: 2012-05-22 Date First Published:

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS

0.01

Percentile

83.5%