J-Security Center

Title: Microsoft Netmeeting CALLTO URL Buffer Overflow Vulnerability

Severity: MODERATE

Description:

Microsoft Netmeeting sessions can be launched through Internet Explorer by browsing to a 'callto:' link. These links usually contain the address of the Netmeeting user to be called and may also contain a directory to retrieve the addressing information from.

It has been reported that clicking on a malformed 'callto:' URI using Internet Explorer may result in Windows failing due to a kernel mode exception. This issue may be due to a boundary condition error in one of the parameters accepted by the CALLTO protocol handler.

Successful exploitation of this vulnerability may result in a denial of service to the system. If this is due to a boundary condition error, it is not currently known if critical memory is overwritten that could allow for code execution.

Symantec was unable to reproduce this vulnerability on a Windows 2000 SP3 system running Internet Explorer 6.0 SP1 and Netmeeting 3.01 using the supplied proof of concept code.

It is important to note that the CALLTO protocol handler does not function by default on browsers other than Internet Explorer.

** It has been reported that when Windows fails in this instance, a pointer may be overwritten. This indicates that code execution could be possible through successful exploitation of this vulnerability.

Affected Products:

  • Microsoft NetMeeting 2.1.0
  • Microsoft NetMeeting 3.0.1 4.4.3385
  • Microsoft Windows 2000 Professional
  • Microsoft Windows 98
  • Microsoft Windows XP Home
  • Microsoft Windows XP Professional

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.