OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
[SA27751] Invensys Wonderware InTouch Insecure NetDDE Share Permissions Security Issue

From: Secunia Security Advisories (sec-advsecunia.com)
Date: Mon Nov 26 2007 - 20:47:06 CST


----------------------------------------------------------------------

2003: 2,700 advisories published
2004: 3,100 advisories published
2005: 4,600 advisories published
2006: 5,300 advisories published

How do you know which Secunia advisories are important to you?

The Secunia Vulnerability Intelligence Solutions allows you to filter
and structure all the information you need, so you can address issues
effectively.

Get a free trial of the Secunia Vulnerability Intelligence Solutions:
http://corporate.secunia.com/how_to_buy/38/vi/?ref=secadv

----------------------------------------------------------------------

TITLE:
Invensys Wonderware InTouch Insecure NetDDE Share Permissions
Security Issue

SECUNIA ADVISORY ID:
SA27751

VERIFY ADVISORY:
http://secunia.com/advisories/27751/

CRITICAL:
Less critical

IMPACT:
System access

WHERE:
From local network

SOFTWARE:
Invensys Wonderware InTouch 8.x
http://secunia.com/product/16628/

DESCRIPTION:
A security issue has been reported in Invensys Wonderware InTouch,
which potentially can be exploited by malicious users to compromise a
vulnerable system.

The problem is that the application creates a NetDDE share with
insecure default permissions. This can potentially be exploited to
execute arbitrary programs that accept NetDDE connections on the
target system.

The security issue is reported in version 8.0.

SOLUTION:
Apply updates or upgrade to version 9.0 or later (see vendor's
advisory for details).

PROVIDED AND/OR DISCOVERED BY:
Discovered by Neutralbit and reported via US-CERT with assistance
from Digital Bond.

ORIGINAL ADVISORY:
Wonderware:
http://pacwest.wonderware.com/web/News/NewsDetails.aspx?NewsThreadID=2&NewsID=201804

US-CERT VU#138633:
http://www.kb.cert.org/vuls/id/138633

----------------------------------------------------------------------

About:
This Advisory was delivered by Secunia as a free service to help
everybody keeping their systems up to date against the latest
vulnerabilities.

Subscribe:
http://secunia.com/secunia_security_advisories/

Definitions: (Criticality, Where etc.)
http://secunia.com/about_secunia_advisories/

Please Note:
Secunia recommends that you verify all advisories you receive by
clicking the link.
Secunia NEVER sends attached files with advisories.
Secunia does not advise people to install third party patches, only
use those supplied by the vendor.

----------------------------------------------------------------------

Unsubscribe: Secunia Security Advisories

----------------------------------------------------------------------