Menu

Database

Intel Centrino Wireless Driver Malformed Beacon SSID IE

WVE ID: WVE-2007-0001

Type: Vulnerability

Status: Candidate

Classification:
Input Manipulation

Description:
A vulnerability exists in the Windows drivers for both the Intel 2200BG and 2915ABG PRO/Wireless chipsets which may allow remote code execution through malformed beacon frames with an overly long SSID information element.

Discussion:
Intel Centrino drivers version 9.0.3.9 for Windows contain a vulnerability that may allow a remote attacker to execute arbitrary code on vulnerable hosts. This vulnerability affects both Intel 2200BG and 2915ABG adapters.

The vulnerability is triggered by parsing 802.11 beacon frames with an overly long SSID information element which causes memory corruption on the target host. Because beacon frames are sent to the broadcast address, an attacker can compromise multiple hosts without targeting an individual station.

The Centrino 9.0.4.17 drivers resolve this vulnerability. It is believed but unconfirmed that all driver versions prior to 9.0.4.17 are vulnerable for the 2200BG and 2915ABG chipsets. Current proof-of-concept exploits trigger a DoS condition on vulnerable hosts, however, it is belived that remote code execution is possible.

Credits
Author: Jon Ellch : None
Author: Breno Silva Pinto : Open Communications Security

References
URL: http://www.securiteam.com/windowsntfocus/6B00D2KHPA.html
CVE: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2006-6651

Released: 2006-12-19

Submitter
Joshua Wright (jwright@arubanetworks.com) : Aruba Networks

Submitted: Thu Jan 04 11:53:09 -0800 2007

Candidate Date: Thu Jan 04 12:05:23 -0800 2007


Recent Entries

TKIP Replay and Plaintext Discovery
WVE-2008-0013 11/18/2008

Active Https Cookie Hijacking
WVE-2008-0012 9/18/2008

Auto Immune Attack
WVE-2008-0011 9/17/2008

Marvell Null SSID Association Request
WVE-2008-0010 9/15/2008

Marvell EAPOL-Key Length Overflow
WVE-2008-0009 9/15/2008

Atheros IE Tag Overflow
WVE-2008-0008 9/15/2008

Weaknesses in the A5/1 Cipher
WVE-2008-0007 4/9/2008

Block ACK DoS
WVE-2008-0006 4/9/2008

GF Mode WIDS Rogue AP Evasion
WVE-2008-0005 4/9/2008

HT Intolerant Degradation of Service
WVE-2008-0004 4/9/2008

More Entries...

News

SANS Institute Sponsors WVE
4/19/2008

Wireless Attackers and Honeypot Technology
4/15/2008

High Speed Risks in 802.11n Slides Posted
4/11/2008

Vulnerabilities in 802.11n
4/9/2008

WVE Editors Speaking at SHARKFEST.08
1/3/2008

More News...