Vigil@nce - Microsoft Service Bus: denial of service via AMQP
July 2014 by Vigil@nce
This bulletin was written by Vigil@nce : http://vigilance.fr/offer
SYNTHESIS OF THE VULNERABILITY
An attacker can send AMQP messages to Microsoft Service Bus for
Windows Server, in order to trigger a denial of service.
Impacted products: Windows 2008, Microsoft Windows 2012
Severity: 2/4
Creation date: 08/07/2014
DESCRIPTION OF THE VULNERABILITY
The Microsoft Service Bus for Windows Server component can be
installed on Windows.
The AMQP (Advanced Message Queuing Protocol) protocol is used to
exchange messages.
However, when Microsoft Service Bus receives a special sequence of
AMQP messages, it stops.
An attacker can therefore send AMQP messages to Microsoft Service
Bus for Windows Server, in order to trigger a denial of service.
ACCESS TO THE COMPLETE VIGIL@NCE BULLETIN
http://vigilance.fr/vulnerability/Microsoft-Service-Bus-denial-of-service-via-AMQP-15011