Windows Explorer Explorer.exe Denial Of Service Vulnerability
BID:18838
CVE-2006-3351 |Info
Windows Explorer Explorer.exe Denial Of Service Vulnerability
| Bugtraq ID: | 18838 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 05 2006 12:00AM |
| Updated: | Jul 06 2006 03:49PM |
| Credit: | nanika has been credited with the discovery of this vulnerability |
| Vulnerable: |
Microsoft Windows Explorer 0 |
| Not Vulnerable: | |
Discussion
Windows Explorer Explorer.exe Denial Of Service Vulnerability
Microsoft Windows Explorer is prone to a denial of service vulnerability. The application fails to handle malicious '.url' files properly while parsing the URI file.
Remote attackers may exploit this issue to crash Internet Explorer, Windows Explorer, and possibly others.
Microsoft Windows Explorer is prone to a denial of service vulnerability. The application fails to handle malicious '.url' files properly while parsing the URI file.
Remote attackers may exploit this issue to crash Internet Explorer, Windows Explorer, and possibly others.
Exploit / POC
Windows Explorer Explorer.exe Denial Of Service Vulnerability
The following examples demonstrate this issue. Note that removing the '.url' file may have to be done through 'cmd.exe', since Windows Explorer may crash when attempting to delete the file.
The following examples demonstrate this issue. Note that removing the '.url' file may have to be done through 'cmd.exe', since Windows Explorer may crash when attempting to delete the file.
Solution / Fix
Windows Explorer Explorer.exe Denial Of Service Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected]
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected]:[email protected]
References
Windows Explorer Explorer.exe Denial Of Service Vulnerability
References:
References:
- Internet Explorer Homepage (Microsoft)
- Windows Explorer URL File format overflow (nanika)