CVE-2019-6453
Summary
| CVE | CVE-2019-6453 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-02-18 15:29:00 UTC |
| Updated | 2020-08-24 17:37:00 UTC |
| Description | mIRC before 7.55 allows remote command execution by using argument injection through custom URI protocol handlers. The attacker can specify an irc:// URI that loads an arbitrary .ini file from a UNC share pathname. Exploitation depends on browser-specific URI handling (Chrome is not exploitable). |
Risk And Classification
Problem Types: CWE-88
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2019-6453: RCE on mIRC <7.55 using argument injection through custom URI protocol handlers · Proof of Calc | MISC | proofofcalc.com | Exploit, Third Party Advisory |
| www.mirc.com/news.html | MISC | www.mirc.com | Product |
| proofofcalc.com/advisories/20190218.txt | MISC | proofofcalc.com | Third Party Advisory |
| GitHub - proofofcalc/cve-2019-6453-poc: Proof of calc for CVE-2019-6453 | MISC | github.com | Exploit, Third Party Advisory |
| ProofOfCalc na Twitterze: "Finally publishing write-up + advisory + PoC for CVE-2019-6453 (RCE on mIRC < 7.55)! Link to the WU: https://t.co/EW43KB2WkV Link to the PoC: https://t.co/F1x1E7qysV -- @_SIben_ @Geluchat" | MISC | twitter.com | Exploit, Third Party Advisory |
| mIRC < 7.55 - 'Custom URI Protocol Handlers' Remote Command Execution - Windows remote Exploit | EXPLOIT-DB | www.exploit-db.com | Exploit, Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.