IBM Security Server Protection for Windows, Proventia Network IDS, Proventia Network MFS, Proventia-G 1.1 and earlier, RealSecure Network, RealSecure Server Sensor, Proventia Desktop, Proventia Network IPS, Proventia Server IPS for Linux technology, Virtual Server Protection for Vmware:
This signature detects a specially-crafted WSDAPI (Web Services for Devices) message that can lead to remote code execution.
High
IBM Security Server Protection for Windows: 2.1.14.2450, IBM Security Server Protection for Windows: 1.0.914.2450, IBM Security Server Protection for Windows: 2.0.300.2450, Proventia Network IDS: XPU 29.110, Proventia Network MFS: XPU 29.110, Proventia-G 1.1 and earlier: XPU 29.110, RealSecure Network: XPU 29.110, RealSecure Server Sensor: XPU 29.110, Proventia Desktop: 2450, Proventia Network IPS: XPU 29.110, Proventia Server IPS for Linux technology: 29.110, Virtual Server Protection for Vmware: 1.0
Microsoft Windows Vista, Microsoft Windows Vista: x64, Microsoft Windows Vista: SP1, Microsoft Windows Vista: SP1 x64, Microsoft Windows Server 2008: Itanium, Microsoft Windows Server 2008: x32, Microsoft Windows Server 2008: x64, Microsoft Windows Vista: SP2 x64, Microsoft Windows Vista: SP2, Microsoft Windows Server 2008: SP2 x32, Microsoft Windows Server 2008: SP2 x64, Microsoft Windows Server 2008: SP2 Itanium
Unauthorized Access Attempt
Microsoft Windows could allow a remote attacker to execute arbitrary code on the system, caused by the improper validation of MIME headers by the Web Service on Devices API (WSDAPI). By sending a specially-crafted WSDAPI message containing a MIME header or a query response to the WSD services running on TCP port 5357 and 5358, a remote attacker could exploit this vulnerability to execute arbitrary code on the system.
Apply the appropriate patch for your system, as listed in Microsoft Security Bulletin MS09-063. See References.
Microsoft Security Bulletin MS09-063
Vulnerability in Web Service on Devices Could Allow Remote Code Execution (973565)
http://www.microsoft.com/technet/security/bulletin/ms09-063.mspx
IBM Internet Security Systems Protection Alert
Microsoft Windows WSDAPI code execution
http://www.iss.net/threats/353.html
ISS X-Force
Microsoft Windows WSDAPI code execution
http://www.iss.net/security_center/static/53985.php
CVE
CVE-2009-2512
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-2512