Microsoft Windows Explorer saved-search File Remote Code Execution Vulnerability
BID:30109
Info
Microsoft Windows Explorer saved-search File Remote Code Execution Vulnerability
| Bugtraq ID: | 30109 |
| Class: | Input Validation Error |
| CVE: |
CVE-2008-1435 |
| Remote: | Yes |
| Local: | No |
| Published: | Jul 08 2008 12:00AM |
| Updated: | Apr 29 2009 06:56PM |
| Credit: | The vendor reported this issue. |
| Vulnerable: |
Microsoft Windows Vista Ultimate 64-bit edition SP1 Microsoft Windows Vista Ultimate 64-bit edition 0 Microsoft Windows Vista Home Premium 64-bit edition SP1 Microsoft Windows Vista Home Premium 64-bit edition 0 Microsoft Windows Vista Home Basic 64-bit edition SP1 Microsoft Windows Vista Home Basic 64-bit edition 0 Microsoft Windows Vista Enterprise 64-bit edition SP1 Microsoft Windows Vista Enterprise 64-bit edition 0 Microsoft Windows Vista Ultimate SP1 Microsoft Windows Vista Ultimate Microsoft Windows Vista SP1 Microsoft Windows Vista Home Premium SP1 Microsoft Windows Vista Home Premium Microsoft Windows Vista Home Basic SP1 Microsoft Windows Vista Home Basic Microsoft Windows Vista Enterprise SP1 Microsoft Windows Vista Enterprise Microsoft Windows Vista 0 Microsoft Windows Server 2008 Standard Edition Release Candidate Microsoft Windows Server 2008 Standard Edition 0 Microsoft Windows Server 2008 for x64-based Systems 0 Microsoft Windows Server 2008 for Itanium-based Systems 0 Microsoft Windows Server 2008 for 32-bit Systems 0 Microsoft Windows Server 2008 Enterprise Edition Release Candidate Microsoft Windows Server 2008 Enterprise Edition 0 Microsoft Windows Server 2008 Datacenter Edition Release Candidate Microsoft Windows Server 2008 Datacenter Edition 0 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 0 |
| Not Vulnerable: | |
Discussion
Microsoft Windows Explorer saved-search File Remote Code Execution Vulnerability
Microsoft Windows Explorer is prone to a remote code-execution vulnerability.
Successfully exploiting this issue will allow attackers to execute arbitrary code with the privileges of the user running the affected application.
Microsoft Windows Explorer is prone to a remote code-execution vulnerability.
Successfully exploiting this issue will allow attackers to execute arbitrary code with the privileges of the user running the affected application.
Exploit / POC
Microsoft Windows Explorer saved-search File Remote Code Execution Vulnerability
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Microsoft Windows Explorer saved-search File Remote Code Execution Vulnerability
Solution:
The vendor has released an advisory and patches. Please see the references for more information.
Microsoft Windows Vista Home Basic 64-bit edition 0
Microsoft Windows Vista Home Premium 64-bit edition SP1
Microsoft Windows Vista Enterprise 64-bit edition SP1
Microsoft Windows Vista Home Premium 64-bit edition 0
Microsoft Windows Server 2008 for x64-based Systems 0
Microsoft Windows Vista Ultimate 64-bit edition 0
Microsoft Windows Vista Home Basic
Microsoft Windows Vista Home Premium
Microsoft Windows Vista Enterprise
Microsoft Windows Vista Ultimate 64-bit edition SP1
Microsoft Windows Server 2008 for Itanium-based Systems 0
Microsoft Windows Vista Ultimate
Microsoft Windows Server 2008 for 32-bit Systems 0
Microsoft Windows Vista Home Premium SP1
Microsoft Windows Vista Enterprise 64-bit edition 0
Microsoft Windows Vista 0
Microsoft Windows Vista Home Basic 64-bit edition SP1
Microsoft Windows Vista Ultimate SP1
Microsoft Windows Vista Home Basic SP1
Microsoft Windows Vista Enterprise SP1
Solution:
The vendor has released an advisory and patches. Please see the references for more information.
Microsoft Windows Vista Home Basic 64-bit edition 0
-
Microsoft Security Update for Windows Vista for x64-based Systems (KB950582)
http://www.microsoft.com/downloads/details.aspx?familyid=74ea0893-7c2f -4fad-ad27-588ad953b046&displaylang=en
Microsoft Windows Vista Home Premium 64-bit edition SP1
-
Microsoft Security Update for Windows Vista for x64-based Systems (KB950582)
http://www.microsoft.com/downloads/details.aspx?familyid=74ea0893-7c2f -4fad-ad27-588ad953b046&displaylang=en
Microsoft Windows Vista Enterprise 64-bit edition SP1
-
Microsoft Security Update for Windows Vista for x64-based Systems (KB950582)
http://www.microsoft.com/downloads/details.aspx?familyid=74ea0893-7c2f -4fad-ad27-588ad953b046&displaylang=en
Microsoft Windows Vista Home Premium 64-bit edition 0
-
Microsoft Security Update for Windows Vista for x64-based Systems (KB950582)
http://www.microsoft.com/downloads/details.aspx?familyid=74ea0893-7c2f -4fad-ad27-588ad953b046&displaylang=en
Microsoft Windows Server 2008 for x64-based Systems 0
-
Microsoft Security Update for Windows Server 2008 x64 Edition (KB950582)
http://www.microsoft.com/downloads/details.aspx?familyid=85d8701d-f8c7 -4079-8a21-a3a9d5ba71ce
Microsoft Windows Vista Ultimate 64-bit edition 0
-
Microsoft Security Update for Windows Vista for x64-based Systems (KB950582)
http://www.microsoft.com/downloads/details.aspx?familyid=74ea0893-7c2f -4fad-ad27-588ad953b046&displaylang=en
Microsoft Windows Vista Home Basic
-
Microsoft Security Update for Windows Vista (KB950582)
http://www.microsoft.com/downloads/details.aspx?familyid=06739ca6-7368 -4acb-bb67-7e8146071a29
Microsoft Windows Vista Home Premium
-
Microsoft Security Update for Windows Vista (KB950582)
http://www.microsoft.com/downloads/details.aspx?familyid=06739ca6-7368 -4acb-bb67-7e8146071a29
Microsoft Windows Vista Enterprise
-
Microsoft Security Update for Windows Vista (KB950582)
http://www.microsoft.com/downloads/details.aspx?familyid=06739ca6-7368 -4acb-bb67-7e8146071a29
Microsoft Windows Vista Ultimate 64-bit edition SP1
-
Microsoft Security Update for Windows Vista for x64-based Systems (KB950582)
http://www.microsoft.com/downloads/details.aspx?familyid=74ea0893-7c2f -4fad-ad27-588ad953b046&displaylang=en
Microsoft Windows Server 2008 for Itanium-based Systems 0
-
Microsoft Security Update for Windows Server 2008 for Itanium-based Systems (KB950582)
http://www.microsoft.com/downloads/details.aspx?familyid=b30ee4f0-850f -4ff3-86a4-663603a0a802
Microsoft Windows Vista Ultimate
-
Microsoft Security Update for Windows Vista (KB950582)
http://www.microsoft.com/downloads/details.aspx?familyid=06739ca6-7368 -4acb-bb67-7e8146071a29
Microsoft Windows Server 2008 for 32-bit Systems 0
-
Microsoft Security Update for Windows Server 2008 (KB950582)
http://www.microsoft.com/downloads/details.aspx?familyid=189a4170-b495 -4904-9cbd-209e7494d303
Microsoft Windows Vista Home Premium SP1
-
Microsoft Security Update for Windows Vista (KB950582)
http://www.microsoft.com/downloads/details.aspx?familyid=06739ca6-7368 -4acb-bb67-7e8146071a29
Microsoft Windows Vista Enterprise 64-bit edition 0
-
Microsoft Security Update for Windows Vista for x64-based Systems (KB950582)
http://www.microsoft.com/downloads/details.aspx?familyid=74ea0893-7c2f -4fad-ad27-588ad953b046&displaylang=en
Microsoft Windows Vista 0
-
Microsoft Security Update for Windows Vista (KB950582)
http://www.microsoft.com/downloads/details.aspx?familyid=06739ca6-7368 -4acb-bb67-7e8146071a29
Microsoft Windows Vista Home Basic 64-bit edition SP1
-
Microsoft Security Update for Windows Vista for x64-based Systems (KB950582)
http://www.microsoft.com/downloads/details.aspx?familyid=74ea0893-7c2f -4fad-ad27-588ad953b046&displaylang=en
Microsoft Windows Vista Ultimate SP1
-
Microsoft Security Update for Windows Vista (KB950582)
http://www.microsoft.com/downloads/details.aspx?familyid=06739ca6-7368 -4acb-bb67-7e8146071a29
Microsoft Windows Vista Home Basic SP1
-
Microsoft Security Update for Windows Vista (KB950582)
http://www.microsoft.com/downloads/details.aspx?familyid=06739ca6-7368 -4acb-bb67-7e8146071a29
Microsoft Windows Vista Enterprise SP1
-
Microsoft Security Update for Windows Vista (KB950582)
http://www.microsoft.com/downloads/details.aspx?familyid=06739ca6-7368 -4acb-bb67-7e8146071a29
References
Microsoft Windows Explorer saved-search File Remote Code Execution Vulnerability
References:
References:
- Microsoft Windows Homepage (Microsoft )
- Avaya Security Advisory ASA-2008-289 (Avaya)
- Microsoft Security Bulletin MS08-038 �?? Important (Microsoft)