Microsoft Internet Explorer mms Protocol Handler Executable Command Line Injection Vulnerability
BID:10879
Info
Microsoft Internet Explorer mms Protocol Handler Executable Command Line Injection Vulnerability
| Bugtraq ID: | 10879 |
| Class: | Input Validation Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 05 2004 12:00AM |
| Updated: | Aug 05 2004 12:00AM |
| Credit: | Discovery is credited to Nicolas Robillard. |
| Vulnerable: |
Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 |
| Not Vulnerable: | |
Discussion
Microsoft Internet Explorer mms Protocol Handler Executable Command Line Injection Vulnerability
A vulnerability has been reported to exist in Microsoft Internet Explorer that may allow remote attackers to pass arbitrary command line arguments to an application associated with the mms: URI protocol handler. Windows Media Player is the application normally associated with this URI protocol handler.
This vulnerability would permit an attacker to influence the invocation arguments for the executable and could result in loss of compromise of various security properties. This may be exploited from a malicious Web page or possibly through HTML email.
It is not known if this issue is specific to the mms: URI protocol handler or if other URI protocol handlers on the system may be similarly affected. This vulnerability could be a general issue in Internet Explorer with many possible attack vectors, although there is not enough information available at this time to make this determination.
A vulnerability has been reported to exist in Microsoft Internet Explorer that may allow remote attackers to pass arbitrary command line arguments to an application associated with the mms: URI protocol handler. Windows Media Player is the application normally associated with this URI protocol handler.
This vulnerability would permit an attacker to influence the invocation arguments for the executable and could result in loss of compromise of various security properties. This may be exploited from a malicious Web page or possibly through HTML email.
It is not known if this issue is specific to the mms: URI protocol handler or if other URI protocol handlers on the system may be similarly affected. This vulnerability could be a general issue in Internet Explorer with many possible attack vectors, although there is not enough information available at this time to make this determination.
Exploit / POC
Microsoft Internet Explorer mms Protocol Handler Executable Command Line Injection Vulnerability
The following example was submitted:
<A HREF=mms:\\."%20/layout%20c>TRY IT</A>
The following example was submitted:
<A HREF=mms:\\."%20/layout%20c>TRY IT</A>
Solution / Fix
Microsoft Internet Explorer mms Protocol Handler Executable Command Line Injection Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Microsoft Internet Explorer mms Protocol Handler Executable Command Line Injection Vulnerability
References:
References:
- Microsoft Internet Explorer 6 Protocol Handler Vulnerability ("Robillard, Nicolas"
)