Microsoft Windows Path Conversion Weakness
BID:17934
CVE-2006-2334 |Info
Microsoft Windows Path Conversion Weakness
| Bugtraq ID: | 17934 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | May 10 2006 12:00AM |
| Updated: | Jul 13 2006 06:48PM |
| Credit: | Mario Ballano Bárcena <[email protected]> discovered this vulnerability. |
| Vulnerable: |
Webroot Spy Sweeper Enterprise 2.0 Webroot Spy Sweeper Enterprise 1.5.1 Webroot Spy Sweeper Enterprise Webroot Spy Sweeper 3.2 Symantec Norton AntiVirus Corporate Edition 8.0 Symantec Norton AntiVirus Corporate Edition 7.61 Symantec Norton AntiVirus Corporate Edition 7.51 Symantec Norton AntiVirus Corporate Edition 7.6 Symantec Norton AntiVirus Corporate Edition 7.5 Symantec Norton AntiVirus Corporate Edition 7.2 Symantec Norton AntiVirus Corporate Edition 7.0 Symantec Norton AntiVirus Corporate Edition 7.60.build 926 Symantec Norton AntiVirus 2006 Symantec Norton AntiVirus 2005 Professional Edition Symantec Norton AntiVirus 2005 11.0.9 Symantec Norton AntiVirus 2005 11.0 Symantec Norton AntiVirus 2005 Symantec Norton AntiVirus 2004 Professional Edition Symantec Norton Antivirus 2004 for Macintosh Symantec Norton AntiVirus 2004 Symantec Norton AntiVirus 2003 Professional Edition Symantec Norton Antivirus 2003 0 Symantec Norton AntiVirus 2002 Professional Edition Symantec Norton AntiVirus 2002 0 Symantec Norton AntiVirus 2001 Professional Edition Symantec Norton AntiVirus 2001 0 Symantec Norton AntiVirus 5.0 2 Symantec Norton AntiVirus 5.0 Symantec Norton AntiVirus 4.0 for NT Symantec Norton AntiVirus 2000 Softwin BitDefender 9.0 Softwin BitDefender 8.0 Softwin BitDefender 7.2 Softwin BitDefender 7.0 Softwin BitDefender PepiMK Software SpyBot Search & Destroy 1.3 Norman Virus Control 5.81 Norman Virus Control 5.7 Norman Virus Control 5.5 Norman Virus Control 5.4 Norman Virus Control 5.3 Norman Virus Control 5.2 Norman Virus Control 5.1 Norman Virus Control 5.0 Microsoft Windows XP Tablet PC Edition SP2 Microsoft Windows XP Tablet PC Edition SP1 Microsoft Windows XP Tablet PC Edition Microsoft Windows XP Professional x64 Edition Microsoft Windows XP Professional SP2 Microsoft Windows XP Professional SP1 Microsoft Windows XP Professional Microsoft Windows XP Media Center Edition SP2 Microsoft Windows XP Media Center Edition SP1 Microsoft Windows XP Media Center Edition Microsoft Windows XP Home SP2 Microsoft Windows XP Home SP1 Microsoft Windows XP Home Microsoft Windows XP Gold 0 Microsoft Windows XP Embedded SP1 Microsoft Windows XP Embedded Microsoft Windows XP 64-bit Edition Version 2003 SP1 Microsoft Windows XP 64-bit Edition Version 2003 Microsoft Windows XP 64-bit Edition SP1 Microsoft Windows XP 64-bit Edition Microsoft Windows XP 0 Microsoft Windows Server 2003 Web Edition SP1 Microsoft Windows Server 2003 Web Edition Microsoft Windows Server 2003 Standard x64 Edition Microsoft Windows Server 2003 Standard Edition SP1 Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Enterprise x64 Edition Microsoft Windows Server 2003 Enterprise Edition Itanium SP1 Microsoft Windows Server 2003 Enterprise Edition Itanium 0 Microsoft Windows Server 2003 Enterprise Edition SP1 Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Datacenter x64 Edition Microsoft Windows Server 2003 Datacenter Edition Itanium SP1 Microsoft Windows Server 2003 Datacenter Edition Itanium 0 Microsoft Windows Server 2003 Datacenter Edition SP1 Microsoft Windows Server 2003 Datacenter Edition Microsoft Windows NT Workstation 4.0 SP6a Microsoft Windows NT Workstation 4.0 SP6 Microsoft Windows NT Workstation 4.0 SP5 Microsoft Windows NT Workstation 4.0 SP4 Microsoft Windows NT Workstation 4.0 SP3 Microsoft Windows NT Workstation 4.0 SP2 Microsoft Windows NT Workstation 4.0 SP1 Microsoft Windows NT Workstation 4.0 Microsoft Windows NT Terminal Server 4.0 SP6a Microsoft Windows NT Terminal Server 4.0 SP6a Microsoft Windows NT Terminal Server 4.0 SP6 Microsoft Windows NT Terminal Server 4.0 SP5 Microsoft Windows NT Terminal Server 4.0 SP4 Microsoft Windows NT Terminal Server 4.0 SP3 Microsoft Windows NT Terminal Server 4.0 SP2 Microsoft Windows NT Terminal Server 4.0 SP1 Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6 Microsoft Windows NT Enterprise Server 4.0 SP5 Microsoft Windows NT Enterprise Server 4.0 SP4 Microsoft Windows NT Enterprise Server 4.0 SP3 Microsoft Windows NT Enterprise Server 4.0 SP2 Microsoft Windows NT Enterprise Server 4.0 SP1 Microsoft Windows NT Enterprise Server 4.0 Microsoft Windows NT 4.0 SP6a Microsoft Windows NT 4.0 SP6 Microsoft Windows NT 4.0 SP5 Microsoft Windows NT 4.0 SP4 Microsoft Windows NT 4.0 SP3 Microsoft Windows NT 4.0 SP2 Microsoft Windows NT 4.0 SP1 Microsoft Windows NT 4.0 Microsoft Windows 2000 Server SP4 Microsoft Windows 2000 Server SP3 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP4 Microsoft Windows 2000 Professional SP3 Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP4 Microsoft Windows 2000 Datacenter Server SP3 Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP4 Microsoft Windows 2000 Advanced Server SP3 Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server Lavasoft Ad-Aware 0 Kaspersky Labs Anti-Virus Personal Pro 5.0 .335 Kaspersky Labs Anti-Virus Personal Pro 5.0 .228 Kaspersky Labs Anti-Virus Personal Pro 5.0 .227 Kaspersky Labs Anti-Virus Personal Pro 5.0 .20 Kaspersky Labs Anti-Virus Personal Pro 5.0 Kaspersky Labs Anti-Virus Personal 5.0.227 Kaspersky Labs Anti-Virus Personal 5.0 .335 Kaspersky Labs Anti-Virus Personal 5.0 .325 Kaspersky Labs Anti-Virus Personal 5.0 .228 Kaspersky Labs Anti-Virus Personal 5.0 Kaspersky Labs Anti-Virus Personal 4.5 .104 Kaspersky Labs Anti-Virus for Windows Workstations 5.0 .335 Kaspersky Labs Anti-Virus for Windows Workstations 5.0 .228 Kaspersky Labs Anti-Virus for Windows Workstations 5.0 .227 Kaspersky Labs Anti-Virus for Windows Workstations 5.0 .200 Kaspersky Labs Anti-Virus for Windows Workstations 5.0 Kaspersky Anti-Virus 5.0.372 Kaspersky Anti-Virus 5.0.335 Kaspersky Anti-Virus 5.0.228 Kaspersky Anti-Virus 5.0.227 H+BEDV AntiVir Windows Workstation 6.30 .0.5 H+BEDV AntiVir Windows Workstation 6.28 .00.07 H+BEDV AntiVir Windows Workstation 6.28 .00.01 H+BEDV AntiVir Windows Server NT/2000/2003 6.28 .01.10 H+BEDV AntiVir Windows Server NT/2000/2003 6.28 .01.03 H+BEDV AntiVir Personal 6.31 .00.01 Frisk Software F-Prot Antivirus for Windows Eset NOD32 Antivirus 2.51.26 Eset NOD32 Antivirus 2.5 Eset NOD32 Antivirus 1.0 13 Eset NOD32 Antivirus 1.0 12 Eset NOD32 Antivirus 1.0 11 AVG AVG Anti-Virus 7.1.308 AVG AVG Anti-Virus 7.0.323 AVG AVG Anti-Virus 7.0.251 AVG AVG Anti-Virus 7.0 AVG AVG Anti-Virus 6.0.710 Avast Antivirus Server Edition 4.6.489 Avast Antivirus Server Edition 4.6.460 Avast Antivirus Professional Edition 4.6.691 Avast Antivirus Professional Edition 4.6.665 Avast Antivirus Professional Edition 4.6.652 Avast Antivirus Professional Edition 4.6.603 Avast Antivirus Professional Edition 4.6 Avast Antivirus Professional Edition 4.0 Avast Antivirus Managed Client 4.6.394 Avast Antivirus Managed Client Avast Antivirus Home Edition 4.6.691 Avast Antivirus Home Edition 4.6.665 Avast Antivirus Home Edition 4.6.655 Avast Antivirus Home Edition 4.6.652 Avast Antivirus Home Edition 4.6 Avast Antivirus Home Edition 4.0 |
| Not Vulnerable: | |
Discussion
Microsoft Windows Path Conversion Weakness
Microsoft Windows is susceptible to a path-conversion weakness that may allow attackers to bypass security applications. This issue occurs because the operating system uses multiple differing algorithms to resolve file paths.
Attackers may exploit this issue to bypass security software such as antivirus and antispyware products. Other attacks may also be possible.
Any software using the affected function (or APIs and other functions that in turn use the affected function) may be affected by this issue. Specific information regarding affected software and versions is known to be incomplete and possibly inaccurate. This BID will be updated as further information is disclosed.
Microsoft Windows is susceptible to a path-conversion weakness that may allow attackers to bypass security applications. This issue occurs because the operating system uses multiple differing algorithms to resolve file paths.
Attackers may exploit this issue to bypass security software such as antivirus and antispyware products. Other attacks may also be possible.
Any software using the affected function (or APIs and other functions that in turn use the affected function) may be affected by this issue. Specific information regarding affected software and versions is known to be incomplete and possibly inaccurate. This BID will be updated as further information is disclosed.
Exploit / POC
Microsoft Windows Path Conversion Weakness
The following script will demonstrate creating a file that triggers this issue:
The following script will demonstrate creating a file that triggers this issue:
Solution / Fix
Microsoft Windows Path Conversion Weakness
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Kaspersky has released updates to address this issue in affected products. Users are advised to contact Kaspersky for details on obtaining the appropriate updates.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected]:[email protected].
Kaspersky has released updates to address this issue in affected products. Users are advised to contact Kaspersky for details on obtaining the appropriate updates.
References
Microsoft Windows Path Conversion Weakness
References:
References:
- 48Bits Advisory: Path conversion design flaw in NTDLL (48Bits.com)
- Windows XP Homepage (Microsoft)
- [48Bits.com Advisory] Path conversion design flaw in Microsoft NTDLL ("48Bits.com \[I+D Team\]"
)