N-Stalker - The Web Security Specialists

Language Box
Customer Login Box Customer Login

MS ASN.1 Buffer Overflow Vulnerabilities

A high critical vulnerability was announced today by Microsoft that affect libraries which are used to process ASN.1 encoded data. ASN.1 is the standard which defines how data in digital certificates is encoded.

Every application that makes use of MSASN1.DLL or CRYPT32.DLL (for digital certificates handling) is considered to be vulnerable. Some of it includes:

  • SSL (IIS, IE, Outlook)
  • IPSEC (VPN)
  • S/MIME (Mail Clients)
  • Kerberos (Domain Controllers)
  • NTLMv2 (Authentication)
  • Any other product that makes use of digital certificates (except those statically or dynamically linked to openssl library).

Customers must take an immediate action to patch their systems, specially those that are directly connected to a public network (like MS IIS for instance). The Microsoft's Security Bulletin (MS04-007) is available here.

© Copyright 2000-2008 N-Stalker | All rights reserved Legal Notice | Terms of Use