Microsoft Windows Explorer Preview Pane Script Injection Vulnerability
BID:13248
Info
Microsoft Windows Explorer Preview Pane Script Injection Vulnerability
| Bugtraq ID: | 13248 |
| Class: | Input Validation Error |
| CVE: |
CVE-2005-1191 |
| Remote: | Yes |
| Local: | No |
| Published: | Apr 19 2005 12:00AM |
| Updated: | Jul 12 2009 02:06PM |
| Credit: | Discovered by Grey Magic Software. |
| Vulnerable: |
Microsoft Windows ME Microsoft Windows 98SE Microsoft Windows 98 Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Discussion
Microsoft Windows Explorer Preview Pane Script Injection Vulnerability
Microsoft Windows Explorer is prone to a script injection vulnerability. This occurs when the Windows Explorer preview pane (Web View) is enabled on Windows 2000 computers. Windows 98/98SE/ME are also affected by this issue. If a file with malicious attributes is selected using Explorer, script code contained in the attribute fields may be executed with the privilege level of the user that invoked Explorer. This could be exploited to gain unauthorized access to the vulnerable computer in the context of the currently logged in user.
Microsoft Windows Explorer is prone to a script injection vulnerability. This occurs when the Windows Explorer preview pane (Web View) is enabled on Windows 2000 computers. Windows 98/98SE/ME are also affected by this issue. If a file with malicious attributes is selected using Explorer, script code contained in the attribute fields may be executed with the privilege level of the user that invoked Explorer. This could be exploited to gain unauthorized access to the vulnerable computer in the context of the currently logged in user.
Exploit / POC
Microsoft Windows Explorer Preview Pane Script Injection Vulnerability
The following exploits are available:
The following exploits are available:
Solution / Fix
Microsoft Windows Explorer Preview Pane Script Injection Vulnerability
Solution:
Microsoft has released a security bulletin to address this issue for supported platforms.
Microsoft Windows 2000 Advanced Server SP3
Microsoft Windows 2000 Advanced Server SP4
Microsoft Windows 2000 Server SP3
Microsoft Windows 2000 Server SP4
Microsoft Windows 2000 Professional SP3
Microsoft Windows 2000 Professional SP4
Solution:
Microsoft has released a security bulletin to address this issue for supported platforms.
Microsoft Windows 2000 Advanced Server SP3
-
Microsoft Security Update for Windows 2000 (KB894320)
http://www.microsoft.com/downloads/details.aspx?familyid=67581D32-743F -44FF-9B53-30277C196923&displaylang=en
Microsoft Windows 2000 Advanced Server SP4
-
Microsoft Security Update for Windows 2000 (KB894320)
http://www.microsoft.com/downloads/details.aspx?familyid=67581D32-743F -44FF-9B53-30277C196923&displaylang=en
Microsoft Windows 2000 Server SP3
-
Microsoft Security Update for Windows 2000 (KB894320)
http://www.microsoft.com/downloads/details.aspx?familyid=67581D32-743F -44FF-9B53-30277C196923&displaylang=en
Microsoft Windows 2000 Server SP4
-
Microsoft Security Update for Windows 2000 (KB894320)
http://www.microsoft.com/downloads/details.aspx?familyid=67581D32-743F -44FF-9B53-30277C196923&displaylang=en
Microsoft Windows 2000 Professional SP3
-
Microsoft Security Update for Windows 2000 (KB894320)
http://www.microsoft.com/downloads/details.aspx?familyid=67581D32-743F -44FF-9B53-30277C196923&displaylang=en
Microsoft Windows 2000 Professional SP4
-
Microsoft Security Update for Windows 2000 (KB894320)
http://www.microsoft.com/downloads/details.aspx?familyid=67581D32-743F -44FF-9B53-30277C196923&displaylang=en
References
Microsoft Windows Explorer Preview Pane Script Injection Vulnerability
References:
References:
- Microsoft Security Bulletin MS05-024 (Microsoft)
- File Selection May Lead to Command Execution (GM#015-IE) (GreyMagic Security
)