SA943521: XP, IE7 e Falla Gestione URI

ERCOLINO

Membro dello Staff
Amministratore
Registrato
3 Marzo 2003
Messaggi
252.677
Località
Torino
Microsoft ha pubblicato ieri il Security Advisory 943521, dedicato ad una vulnerabilità isolata nella gestione degli URI in Windows XP SP2 e Windows 2003 SP1/SP2 in presenza di Internet Explorer 7. Microsoft afferma che Windows Vista non è vulnerabile al problema di sicurezza. Inoltre l'azienda non è a conoscenza di attuali tentativi di attacco "in-the-wild" che sfruttano la vulnerabilità.


Dettagli
 
Secunia Advisory: SA26201
Release Date: 2007-07-26
Last Update: 2007-10-11

Critical: Highly critical
Impact: System access
Where: From remote
Solution Status: Unpatched


OS:
Microsoft Windows Server 2003 Datacenter Edition
Microsoft Windows Server 2003 Enterprise Edition
Microsoft Windows Server 2003 Standard Edition
Microsoft Windows Server 2003 Web Edition
Microsoft Windows XP Home Edition
Microsoft Windows XP Professional

Software: Microsoft Internet Explorer 7.x


This advisory is currently marked as unpatched!
- Companies can be alerted when a patch is released!


Description:
A vulnerability has been discovered in Microsoft Windows, which can be exploited by malicious people to compromise a vulnerable system.

The vulnerability is caused due to an input validation error within the handling of URIs with registered URI handlers (e.g. "mailto", "news", "nntp", "snews", "telnet", and "http"). This can be exploited to execute arbitrary commands when a user of certain applications (e.g. Firefox) visits a malicious website or clicks on a link with a specially crafted URI containing a "%" character and ending with a certain extension (e.g. ".bat" or ".cmd").


Examples:
mailto:test%../../../../windows/system32/calc.exe".cmd
nntp:../../../../../Windows/system32/telnet.exe" "secunia.com 80%.bat

Successful exploitation requires that Internet Explorer 7 is installed on the system.

The following applications have been identified as attack vectors on a fully patched Windows XP SP2 and Windows Server 2003 SP2 system:
* Firefox version 2.0.0.5
* Netscape Navigator version 9.0b2
* mIRC version 6.3
* Adobe Reader/Acrobat version 8.1 and prior (when opening PDF files)
* Outlook Express 6 (e.g. when following specially crafted links in VCards)
* Outlook 2000 (e.g. when following specially crafted links in VCards)

Other versions and applications may also be affected.

Solution:
Do not browse untrusted websites, follow untrusted links, or open untrusted .PDF files.



Bollettino Sicurezza
 
Indietro
Alto Basso