Crystal Reports flaw affects Visual Studio, Outlook

TechRepublic
Microsoft has patched a vulnerability in the Web viewing component of Crystal Reports. This component is used in Visual Studio .NET 2003, Outlook 2003 (when used with Business Contact Manager), and Microsoft's CRM solution.

The source of the threat is a Directory Transversal Vulnerability, CAN-2004-0204. This can result in a denial of service event or a confidential information disclosure.

MBSA (Microsoft Baseline Security Analyzer) can't detect this problem, but the Systems Management Server (SMS) will report if the update is needed.

According to Microsoft Security Bulletin MS04-017, "Vulnerability in Crystal Reports Web Viewer Could Allow Information Disclosure and Denial of Service," the vulnerable component is the CrystalDecisions.Web.dll file earlier than version 9.1.9800.9.

Patches are available, and there are several possible workarounds.

This flaw affects:

  • Visual Studio .NET 2003 (only if IIS was installed at the time VS.NET 2003 was installed).
  • Outlook 2003 with Business Contact Manager (only if installed at a time when IIS was already installed).
  • Microsoft Business Solutions CRM 1.2.

For the first two pieces of software, any authenticated or anonymous user accessing Crystal Reports Web Viewer can attack using this vulnerability. For CRM 1.2, only authenticated users are capable of launching an attack because they are the only ones who can access the Web Viewer. The threats that are dependent on an IIS installation are due to the different default installation triggered by the presence of IIS.

Microsoft reports that no other versions of these programs are affected by this vulnerability.

Risk level
Microsoft rates this as only a moderate threat, but it bases its evaluation in part on how many people are using the affected products. Since the threat in MS04-017 applies to products that don't ship with every Windows computer, the company rates the threat as only moderate.

However, when I determine threat levels, I normally look at the potential damage to those who are using the vulnerable programs. After all, if your systems can be easily compromised by a flaw, it is little consolation if few others are vulnerable. Therefore, I rate the threat level of this vulnerability as high because a successful attacker could view or modify database files, probably without leaving a trace. The actual level of threat would depend in great part on how critical the information stored in the database is; however, a good firewall configuration would greatly reduce the risk.

This isn't one of those really big threats, but it can cause a lot of problems and requires your attention if you are managing the affected products.

Mitigating factors
1. Only systems with Internet Information Services (IIS) installed are vulnerable.

2. Good firewall security practices should block this attack.

3. Microsoft reports, "The attack is only effective against files where the IIS worker process that is hosting the CrystalDecisions.Web.dll file has delete permissions." Whether this means that the exploit couldn't also be used to view unauthorised files wasn't made clear in the bulletin.

One workaround is that since this only affects systems with IIS installed, disabling IIS would block any attack through this vector. According to Microsoft, executing the net stop w3svc command is actually all that is required to disable IIS. This would, of course, terminate Web content access. See the Security Bulletin for additional workarounds, as well as patches for the affected products.

TechRepublic is the online community and information resource for all IT professionals, from support staff to executives. We offer in-depth technical articles written for IT professionals by IT professionals. In addition to articles on everything from Windows to e-mail to firewalls, we offer IT industry analysis, downloads, management tips, discussion forums, and e-newsletters.

©2004 TechRepublic, Inc.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

Terms of Service - As a ZDNet registrant, and by using this service, you indicate that you agree to our Terms and Conditions and have read and understand our Privacy Policy.

ZDNet Australia Live

Why you can't afford to resist the cloud
http://t.co/b3l1tvuE #cloudcomputing

Facebook Platform experiencing JS SDK issues http://t.co/AW8sGj8F

look at aimersoft dvd to iphone converter for promotion code aimersoft dvd to iphone converter for less

51 minutes ago by Dypowgenny on Dear computer mouse: You're dumped

NBN truck halted by manufacturing fault http://t.co/LvGfwocN

Travel Tech Q&A: Dodo's Larry Kestelman http://t.co/n4TYTAep

I agree that the NSWDET, is becoming a bit excessive with their blocking of sites. It is especially infuriating when I constantly visit a...

1 hour ago by KallinaMiran on Teachers attack NSW DET filter

Facebook Platform experiencing JS SDK issues http://t.co/ra9COk6d

Travel Tech Q and A: Dodo's Larry Kestelman http://t.co/b58O1A0Z

Web research on the iPad using Evernote and Skitch (how-to) | ZDNet http://t.co/DUfwleVz via @twttimes

Travel Tech Q&A: Dodo's Larry Kestelman - ZDNet Australia: Travel Tech Q&A: Dodo's Larry KestelmanZDNet Australi... http://t.co/MTPXWwiz

"If you want to understand why a company acts the way it does, just follow the money". Microsoft, Apple and Google http://t.co/0GwAIRSo

Never hold it in again! DOHA tenders for Toilet Map back-end - #GIS http://t.co/HCtEgLA3 via @zdnetaustralia

Why #smallbiz should care about the megaupload debacle: http://t.co/9i7Zrdw9 #SMEs #SMBs

Sex Tech Weekly: Megaupload, Match Singles Data, Obscenity Copyright, China Porn Spam Kings http://t.co/fVBJwY1z

Europeans may not implement ACTA due to Poland retraction. http://t.co/suY9It1i

Microsoft, Apple, and Google: where does the money come from? http://t.co/WIvDSxOH

Surprise-Facebook, Twitter more addictive than alcohol, tobacco
http://t.co/MUPU2QZs

#Facebook #apps trippls at work @futureworkplace @slbootcamp #slbootcamp - http://t.co/jHjm7d42

#Facebook #apps trippls at work @2020Workplace @futureworkplace #slbootcamp - http://t.co/h8ZZCiSo

Poland sees the light and suspects its process to approve the ACTA: http://t.co/jDvu441Z

Reality bites! Ouch for startup booom... http://t.co/w2X2SwUW

RT @almaujudy: Reality bites! Ouch for startup booom... http://t.co/w2X2SwUW

Chris Dodd and the MPAA: bribery or politics as usual? - ZDNet (blog)

RT @kylepace: Web research on the iPad using Evernote and Skitch (how-to): http://t.co/ElQgO8kJ #edtech #mlearning

RT @yelvington: German smackdown of Apple knocks iProducts off market http://t.co/rQmNZSFi maybe they shouldn't have started this patent war.

Gadget Reviews Samsung Replenish - onyx black (Boost Mobile) http://t.co/VCISMrjI Via ZDnet

Samsung Replenish - onyx black (Boost Mobile): Keep in mind that the Samsung Replenish is an entry-l... http://t.co/raP6rBPC LR=U1281182

#IBM, USC use #Twitter to pick favorite quarterback in #SuperBowl http://t.co/ZZWPa9Yp

RT @asaunders: Another old friend abandons ship. http://t.co/PHAxktwh

RT @hackernewsbot: The 'Startup Boom' is a disguised jobs fair for big corporations... http://t.co/ArR7HgIc

Be everywhere: Google’s real social strategy | ZDNet http://t.co/vrwZOKYP via @kuratcom

RT @ingramchen: Silicon Valley's dirty little secret: The 'Startup Boom' is a disguised jobs fair for big corporations http://t.co/3ZCChSI7

Apple, google, microsoft. Where does the money come from and how it affects behaviour. - http://t.co/QHfcBgxJ

Amped #Wireless #High #Power Wireless-N 600mW #Gigabit #Router (R10000G) http://t.co/eQLSpcHc

RT @applespotlight: Where the money comes from:
Apple vs Microsoft vs Google
http://t.co/vNTZ2eYO

Web research on the iPad using Evernote and Skitch (how-to) http://t.co/U2whUhni via @zite #edchat

RT @Techmeme: Windows Phone developer lead leaves for Amazon's Kindle team (@maryjofoley / All about... http://t.co/OX7Zo2tK http://t.co/M7Ooyj1A

Hi guys! http://s017.radikal.ru/i409/1111/3d/1ed945824087.gif http://coedmagazine.files.wordpress.com/2010/1...

5 hours ago by EffeftHem on Abetz shifted in reshuffle

here is link to the hip area to megauploade megauploade http://173.192.82.7/ i'm also asking you to portion the join...

7 hours ago by wepUnpardarem on Filter legislation not drafted: govt forum

......ummm, The NBN is an investment and one that will bring the world to us and not further away. BTW THE NBN IS AN INVESTMENT AND ONE T...

10 hours ago by wesley5500 on Abbott paving a telecoms road to nowhere

We purchased a new W7 PC over 6 months back but no-one in this house bothers to use it. W7 constantly refuses to play nice with XP on our...

12 hours ago by grump on Windows XP clings on as dominant OS

Apple forced to remove 3G iPad2, iPhone 3GS & iPhone 4 from Germany online store. It seems like the Motorola patents which Google is acq...

17 hours ago by myproffs on ITC rejects Apple's battle with Motorola

Yes thats the idea of a diploma or degree, isnt it?

18 hours ago by SAMUAL on Union fires up over Westpac outsourcing

Hi! my identify is Jully. I would like to meemeet admissible attendant :) This is my homepage [url=]http://jskdh5jkd7djh4.com/[/url]l...

19 hours ago by Speedgekelp on Broadband Speedtest

ipod pakistan

20 hours ago by rattJurse on Can CEO-in-waiting give AMD a jumpstart?

I had no idea westpac had such financial problems that they have to slash staff. Quick everyone pull your money out of them quick. I wa...

20 hours ago by deonast on Tech jobs to go in Westpac cuts

Online shopping is best option for time&money saving. Choose authentic stores to buy branded products. Find Online Shopping& money saving...

20 hours ago by ManishG on Shopping online: so much more than GST

to buy imtoo dvd to iphone converter suprisely imtoo dvd to iphone converter for gift

21 hours ago by leawlrichard on Online retail fails Gen Y impatience test

Opracowano ponad 2000 definicji public relations]. Podstawowy schemat zawiera po pierwsze, Organizacje, realizujaca misje o charakterze p...

21 hours ago by AgencjaPr on iiNet undercuts Internode with NBN pricing

I am sure you will love imtoo dvd to iphone converter to get new coupon imtoo dvd to iphone converter , just clicks away

21 hours ago by Snawncamie on Oz start-ups hamstrung by lack of vision

I'm sure the best for you imtoo dvd to iphone converter online shopping imtoo dvd to iphone converter and check coupon code available

22 hours ago by hoaspvernia on Telstra, not gormless Libs, plaguing Conroy

buy best xilisoft dvd to iphone converter with confident for less

22 hours ago by Dypowrobbyn on Hackers should be given a second chance

"That's why we need an NBN fibre to the node, to supply backhaul to ADSL exchanges" None of that actually makes any sense. "but we do ...

22 hours ago by Hubert Cumberdale on Abbott paving a telecoms road to nowhere

"but not at any cost!!!!!" What in your opinion would be an acceptable cost to build a FTTH network covering 93% of premises in Australi...

22 hours ago by Hubert Cumberdale on Abbott paving a telecoms road to nowhere

sell xilisoft dvd to iphone converter for more with confident

22 hours ago by leawlmarna on Went to Gartner. All I got was this podcast

This story has been voted 5 times in the last 24 hours!

1 day ago, Abbott paving a telecoms road to nowhere

Facebook Activity

Keep up with ZDNet Australia

ZDNet Events Calendar

ZDNet Events Calendar