Home Page | Skip to Navigation | Skip to Content | Skip to Search | Skip to Footer

Update Protection against Microsoft TCP/IP DHCP Denial Of Service Vulnerability (MS08-004)

Subscribe

Check Point Reference: CPAI-2008-026
Date Published:
Severity:
Last Updated:
Source: Microsoft Security Bulletin MS08-004
Industry Reference(s): CVE-2008-0084
Protection Provided by: VPN-1
  • NGX R65
  • NGX R62
  • NGX R61
  • NGX R60
VSX
  • NGX R65
IPS-1
  • IPS-1
Who is Vulnerable?
Windows Vista
Windows Vista x64 Edition
Vulnerability Description
A denial of service vulnerability has been reported in the Microsoft Windows TCP/IP handling of certain DHCP packets. The Dynamic Host Configuration Protocol (DHCP) provides central management of IP addresses and other details related to the IP configuration used on the network. An attacker can exploit this vulnerability by sending a specially crafted packet through a malicious DHCP server. This may result in a denial of service condition on the vulnerable host.
Update/Patch Available
Apply patches:
Microsoft Security Bulletin MS08-004
Vulnerability Details
The vulnerability is due to an error in Microsoft Windows TCP/IP that fails to properly handle malformed DHCP packets. To trigger this issue, an attacker may create a malicious DHCP server and send packets through it to a vulnerable host. Successful exploitation may create a denial of service condition on the target host.

Protection Overview
By enabling this protection, SmartDefense will detect and block malformed DHCP packets sent from a malicious server.

In order for the protection to be activated, update your VPN-1/IPS-1 product to the latest SmartDefense update. For information on how to update SmartDefense, go to SBP-2006-05, Protection tab and select the version of your choice.

To configure the defense, select your product from the list below and follow the related protection steps.

VPN-1 NGX R65 & R62

How Can I Protect My Network?
1. In the SmartDefense tab, click Network Security > IP and ICMP > Block DHCP DoS Vulnerability (MS08-004).
2. In the configuration pane, under Settings > Mode, check Active.
3. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: DHCP Protocol Enforcement Violation
Attack Information: DHCP DoS vulnerability detected (MS08-004)

VPN-1 NGX R61 & R60

How Can I Protect My Network?
1. In the SmartDefense tab, click Network Security > IP and ICMP.
2. Select the following protection:

Block DHCP DoS Vulnerability (MS08-004)

3. In the configuration pane, under Settings > Mode, check Active.
4. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: DHCP Protocol Enforcement Violation
Attack Information: DHCP DoS vulnerability detected (MS08-004)

VPN-1 VSX NGX R65

How Can I Protect My Network?
1. In the SmartDefense tab, click Network Security > IP and ICMP > Block DHCP DoS Vulnerability (MS08-004).
2. In the configuration pane, under Settings > Mode, check Active.
3. Install policy on all modules.

How Do I Know if My Network is Under Attack?
SmartView Tracker will log the following entries:

Attack Name: DHCP Protocol Enforcement Violation
Attack Information: DHCP DoS vulnerability detected (MS08-004)

IPS-1

How Can I Protect My Network?
1. In the IPS-1 Policy Manager, under the Protection tab, click Protection Settings > DHCP > DHCP RFC Compliance.
2. Select the following protection:

DHCP Server Assigned Invalid Address to Client

3. In the Protection Settings pane, under Settings check Active or Active upon Confidence.
4. Install policy.

How Do I Know if My Network is Under Attack?
The Alert Browser will log the following entries:

Protection Group: DHCP Message Compliance
Protection Name: DHCP Server Assigned Invalid Address to Client