
====================================================================

                                CERT-Renater

                      Note d'Information No. 2012/VULN119
____________________________________________________________________

DATE                : 14/03/2012

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S) : Windows versions 7, XP, Server 2003, Vista,
                       Server 2008 running Windows Remote Desktop Protocol.

======================================================================
KB2671387
http://technet.microsoft.com/en-us/security/bulletin/ms12-020
_______________________________________________________________________


Microsoft Security Bulletin MS12-020 - Critical Vulnerabilities in
Remote Desktop Could Allow Remote Code Execution (2671387)

   Published: Tuesday, March 13, 2012

   Version: 1.0

General Information

Executive Summary

   This security update resolves two privately reported vulnerabilities in
   the Remote Desktop Protocol. The more severe of these vulnerabilities
   could allow remote code execution if an attacker sends a sequence of
   specially crafted RDP packets to an affected system. By default, the
   Remote Desktop Protocol (RDP) is not enabled on any Windows operating
   system. Systems that do not have RDP enabled are not at risk.

   This security update is rated Critical for all supported releases of
   Microsoft Windows. For more information, see the subsection, Affected
   Software, in this section.

Affected Software
   Windows XP Service Pack 3
   Windows XP Professional x64 Edition Service Pack 2
   Windows Server 2003 Service Pack 2
   Windows Server 2003 x64 Edition Service Pack 2
   Windows Server 2003 with SP2 for Itanium-based Systems
   Windows Vista Service Pack 2
   Windows Vista x64 Edition Service Pack 2
   Windows Server 2008 for 32-bit Systems Service Pack 2
   Windows Server 2008 for x64-based Systems Service Pack 2
   Windows Server 2008 for Itanium-based Systems Service Pack 2
   Windows 7 for 32-bit Systems
   Windows 7 for 32-bit Systems Service Pack 1
   Windows 7 for x64-based Systems
   Windows 7 for x64-based Systems Service Pack 1
   Windows Server 2008 R2 for x64-based Systems
   Windows Server 2008 R2 for x64-based Systems Service Pack 1
   Windows Server 2008 R2 for Itanium-based Systems
   Windows Server 2008 R2 for Itanium-based Systems Service Pack 1

Vulnerability Information

Remote Desktop Protocol Vulnerability - CVE-2012-0002

   A remote code execution vulnerability exists in the way that the Remote
   Desktop Protocol accesses an object in memory that has been improperly
   initialized or has been deleted. An attacker who successfully exploited
   this vulnerability could run abitrary code on the target system. An
   attacker could then install programs; view,change, or delete data; or
   create new accounts with full user rights.

Terminal Server Denial of Service Vulnerability - CVE-2012-0152

   A denial of service vulnerability exists in the way that the Remote
   Desktop Protocol service processes packets. An attacker who
   successfully exploited this vulnerability could cause the target
   service to stop responding.


======================================================================

=========================================================
Les serveurs de référence du CERT-Renater
http://www.cru.fr/securite
http://www.renater.fr
=========================================================
+ CERT-RENATER          | tel : 01-53-94-20-44          +
+ 23 - 25 Rue Daviel    | fax : 01-53-94-20-41          +
+ 75013 Paris           | email: certsvp@renater.fr     +
=========================================================
