exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

urihandlexp.txt

urihandlexp.txt
Posted Oct 6, 2007
Authored by Juergen Schmidt | Site heise-security.co.uk

A URI handling problem on Windows XP affects many applications allowing for the launch of arbitrary applications.

tags | exploit, arbitrary
systems | windows
SHA-256 | 397da5b1bee44f8b26b302d4bb241063b845b2ff0017663598a001d10cd3fa1a

urihandlexp.txt

Change Mirror Download
Hello,

the URI handling problem on Windows XP systems with IE 7 installed hits a
lot of applications, not only Firefox (and mIRC) -- namely Skype, Acrobat
Reader, Miranda, Netscape.

To recap: with the installation of IE 7 Microsoft
changes the handling of URLs that are passed to the operating system on
Windows XP. After this, URLs that contain an invalid "%" encoding can
launch abitrary programms. One example is:

mailto:test%../../../../windows/system32/calc.exe".cmd

that launches the calculator when activated in affected applications.
Firefox fixed this problem in 2.0.6. After being notified by heise
Security, Skype fixed the problem in 3.5.0.239.


Still vulnerable (as of 4th of October) are:

Adobe Acrobat Reader 8.1: If a user clicks on such a link
in a PDF, calc.exe is executed.

Miranda v0.7: If a user klicks on this link in a chat window, calc.exe is
executed

Netscape 7.1: mailto is handled by Netscape itself, but
similar telnet:-links start the calculator.

This list can propably be extended with little effort.


On a question to MSRC if Microsoft is planning to react on this, we
recieved the following response:

"After its thorough investigation, Microsoft has revealed that this is
not a vulnerability in a Microsoft product." 


For further information see:

https://www.heise-security.co.uk/news/96982

bye, ju


--
Juergen Schmidt editor-in-chief heise Security www.heisec.de
Heise Zeitschriften Verlag, Helstorferstr. 7, D-30625 Hannover
Tel. +49 511 5352 300 FAX +49 511 5352 417 EMail ju@heisec.de
GPG-Key: 0x38EA4970, 5D7B 476D 84D5 94FF E7C5 67BE F895 0A18 38EA 4970
Login or Register to add favorites

File Archive:

November 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Nov 1st
    30 Files
  • 2
    Nov 2nd
    0 Files
  • 3
    Nov 3rd
    0 Files
  • 4
    Nov 4th
    12 Files
  • 5
    Nov 5th
    44 Files
  • 6
    Nov 6th
    18 Files
  • 7
    Nov 7th
    9 Files
  • 8
    Nov 8th
    8 Files
  • 9
    Nov 9th
    3 Files
  • 10
    Nov 10th
    0 Files
  • 11
    Nov 11th
    14 Files
  • 12
    Nov 12th
    20 Files
  • 13
    Nov 13th
    63 Files
  • 14
    Nov 14th
    18 Files
  • 15
    Nov 15th
    8 Files
  • 16
    Nov 16th
    0 Files
  • 17
    Nov 17th
    0 Files
  • 18
    Nov 18th
    18 Files
  • 19
    Nov 19th
    7 Files
  • 20
    Nov 20th
    0 Files
  • 21
    Nov 21st
    0 Files
  • 22
    Nov 22nd
    0 Files
  • 23
    Nov 23rd
    0 Files
  • 24
    Nov 24th
    0 Files
  • 25
    Nov 25th
    0 Files
  • 26
    Nov 26th
    0 Files
  • 27
    Nov 27th
    0 Files
  • 28
    Nov 28th
    0 Files
  • 29
    Nov 29th
    0 Files
  • 30
    Nov 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close