Reported March 19, 2003, by Microsoft.

 

 

VERSIONS AFFECTED

 

·         Microsoft ISA Server

 

DESCRIPTION

 

A new vulnerability in Microsoft ISA Server can result in a Denial of Service (DoS) condition. This vulnerability stems from a flaw in the way ISA Server’s DNS intrusion-detection application filter handles a specific type of request when the filter scans incoming DNS requests. To exploit this vulnerability, an attacker can send a specially formed request to an ISA Server computer that is publishing a DNS server, resulting in a DoS to the published DNS server. DNS requests arriving at ISA Server would stop at the firewall and not pass through to the internal DNS server.

 

VENDOR RESPONSE

 

Microsoft has released Security Bulletin MS03-009, “Flaw In ISA Server DNS Intrusion Detection Filter Can Cause Denial Of Service (331065),” to address this vulnerability and recommends that affected users immediately apply the patch mentioned in the bulletin.

 

CREDIT

Discovered by Mike Fratto of Network Computing Magazine.