ID

VAR-200205-0126


CVE

CVE-2002-0224


TITLE

Microsoft MSDTC Service Denial of Service Attack Vulnerability (MS02-018)

Trust: 0.6

sources: CNNVD: CNNVD-200205-013

DESCRIPTION

The MSDTC (Microsoft Distributed Transaction Service Coordinator) for Microsoft Windows 2000, Microsoft IIS 5.0 and SQL Server 6.5 through SQL 2000 0.0 allows remote attackers to cause a denial of service (crash or hang) via malformed (random) input. It is installed by default on Windows 2000, as well as with Microsoft SQL Server 6.5 and higher. It has been reported that it is possible to cause this service to crash by sending 1024 bytes of random data to its listening port, by default port 3372. Restarting the service will reportedly allow it to resume normal operation. The existence of this vulnerability has not been confirmed by Microsoft. * Further reports indicate that sending approximately 20200 null bytes to the service, will cause the entire system to become unresponsive

Trust: 1.17

sources: NVD: CVE-2002-0224 // BID: 4006

AFFECTED PRODUCTS

vendor:microsoftmodel:sql serverscope:eqversion:2000

Trust: 1.9

vendor:microsoftmodel:sql serverscope:eqversion:7.0

Trust: 1.9

vendor:microsoftmodel:sql serverscope:eqversion:6.5

Trust: 1.9

vendor:microsoftmodel:internet information servicesscope:eqversion:5.0

Trust: 1.0

vendor:microsoftmodel:windows 2000scope:eqversion:*

Trust: 1.0

vendor:microsoftmodel:internet information serverscope:eqversion:5.0

Trust: 0.6

vendor:microsoftmodel:windows 2000scope:eqversion:sp2

Trust: 0.6

vendor:microsoftmodel:windows server sp2scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows server sp1scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows serverscope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows professional sp2scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows professional sp1scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows professionalscope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows datacenter server sp2scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows datacenter server sp1scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows datacenter serverscope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows advanced server sp2scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows advanced server sp1scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:windows advanced serverscope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:sql server sp2scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:sql server sp1scope:eqversion:2000

Trust: 0.3

vendor:microsoftmodel:sql server sp3 alphascope:eqversion:7.0

Trust: 0.3

vendor:microsoftmodel:sql server sp3scope:eqversion:7.0

Trust: 0.3

vendor:microsoftmodel:sql server sp2 alphascope:eqversion:7.0

Trust: 0.3

vendor:microsoftmodel:sql server sp2scope:eqversion:7.0

Trust: 0.3

vendor:microsoftmodel:sql server sp1 alphascope:eqversion:7.0

Trust: 0.3

vendor:microsoftmodel:sql server sp1scope:eqversion:7.0

Trust: 0.3

vendor:microsoftmodel:sql server alphascope:eqversion:7.0

Trust: 0.3

vendor:microsoftmodel:iisscope:eqversion:5.0

Trust: 0.3

sources: BID: 4006 // CNNVD: CNNVD-200205-013 // NVD: CVE-2002-0224

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2002-0224
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-200205-013
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2002-0224
severity: MEDIUM
baseScore: 5.0
vectorString: AV:N/AC:L/AU:N/C:N/I:N/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: NONE
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 2.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.0

sources: CNNVD: CNNVD-200205-013 // NVD: CVE-2002-0224

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

sources: NVD: CVE-2002-0224

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-200205-013

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-200205-013

EXTERNAL IDS

db:NVDid:CVE-2002-0224

Trust: 1.9

db:BIDid:4006

Trust: 1.9

db:BUGTRAQid:20020131 MSDTC ON 3372

Trust: 0.6

db:BUGTRAQid:20020419 KPMG-2002015: MICROSOFT DISTRIBUTED TRANSACTION COORDINATOR DOS

Trust: 0.6

db:XFid:8046

Trust: 0.6

db:CNNVDid:CNNVD-200205-013

Trust: 0.6

sources: BID: 4006 // CNNVD: CNNVD-200205-013 // NVD: CVE-2002-0224

REFERENCES

url:http://www.securityfocus.com/bid/4006

Trust: 2.6

url:http://www.iss.net/security_center/static/8046.php

Trust: 2.6

url:http://online.securityfocus.com/archive/1/268593

Trust: 2.6

url:http://online.securityfocus.com/archive/1/253360

Trust: 2.6

url:http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/ms02-018.asp

Trust: 0.3

sources: BID: 4006 // CNNVD: CNNVD-200205-013 // NVD: CVE-2002-0224

CREDITS

palante@subterrain.net※>palante@subterrain.net</a>※ palante@subterrain.net

Trust: 0.6

sources: CNNVD: CNNVD-200205-013

SOURCES

db:BIDid:4006
db:CNNVDid:CNNVD-200205-013
db:NVDid:CVE-2002-0224

LAST UPDATE DATE

2024-11-22T23:12:10.696000+00:00


SOURCES UPDATE DATE

db:BIDid:4006date:2009-07-11T09:56:00
db:CNNVDid:CNNVD-200205-013date:2006-09-01T00:00:00
db:NVDid:CVE-2002-0224date:2024-11-20T23:38:35.610

SOURCES RELEASE DATE

db:BIDid:4006date:2002-01-31T00:00:00
db:CNNVDid:CNNVD-200205-013date:2002-01-31T00:00:00
db:NVDid:CVE-2002-0224date:2002-05-16T04:00:00