Microsoft VBScript 'winhlp32.exe' 'MsgBox()' Remote Code Execution Vulnerability
BID:38463
Info
Microsoft VBScript 'winhlp32.exe' 'MsgBox()' Remote Code Execution Vulnerability
| Bugtraq ID: | 38463 |
| Class: | Boundary Condition Error |
| CVE: |
CVE-2010-0483 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 26 2010 12:00AM |
| Updated: | Apr 14 2010 11:43PM |
| Credit: | Maurycy Prodeus |
| Vulnerable: |
Microsoft VBScript 5.8 Microsoft VBScript 5.7 Microsoft VBScript 5.6 Microsoft VBScript 5.1 Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Messaging Application Server 0 Avaya Meeting Exchange - Webportal 6.0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 |
| Not Vulnerable: | |
Discussion
Microsoft VBScript 'winhlp32.exe' 'MsgBox()' Remote Code Execution Vulnerability
Microsoft VBScript is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the application. Successful exploits will compromise the application and possibly the underlying computer.
NOTE: Attackers must use social-engineering techniques to convince an unsuspecting user to press the 'F1' key when the attacker's message box prompts them to do so.
NOTE: Microsoft reports that this issue can not be exploited on Windows Vista, Server 2008, 7, or Server 2008 R2.
NOTE: This document previously mentioned a buffer-overflow affecting 'winhlp32.exe'. That issue has been moved to BID 38473 (Microsoft Internet Explorer 'winhlp32.exe' 'MsgBox()' Stack-Based Buffer Overflow Vulnerability) to better document it.
Microsoft VBScript is prone to a remote code-execution vulnerability.
Attackers can exploit this issue to execute arbitrary code in the context of the user running the application. Successful exploits will compromise the application and possibly the underlying computer.
NOTE: Attackers must use social-engineering techniques to convince an unsuspecting user to press the 'F1' key when the attacker's message box prompts them to do so.
NOTE: Microsoft reports that this issue can not be exploited on Windows Vista, Server 2008, 7, or Server 2008 R2.
NOTE: This document previously mentioned a buffer-overflow affecting 'winhlp32.exe'. That issue has been moved to BID 38473 (Microsoft Internet Explorer 'winhlp32.exe' 'MsgBox()' Stack-Based Buffer Overflow Vulnerability) to better document it.
Exploit / POC
Microsoft VBScript 'winhlp32.exe' 'MsgBox()' Remote Code Execution Vulnerability
The following examples are available:
The following examples are available:
Solution / Fix
Microsoft VBScript 'winhlp32.exe' 'MsgBox()' Remote Code Execution Vulnerability
Solution:
The vendor has released an advisory and updates; please see the references for more information.
Microsoft VBScript 5.8
Microsoft VBScript 5.1
Microsoft VBScript 5.7
Microsoft VBScript 5.6
Solution:
The vendor has released an advisory and updates; please see the references for more information.
Microsoft VBScript 5.8
-
Microsoft Security Update for Windows 7 (KB981332)
http://www.microsoft.com/downloads/details.aspx?familyid=C3F76835-0053 -4E53-A451-14255E7A4FC0 -
Microsoft Security Update for Windows 7 for x64-based Systems (KB981332)
http://www.microsoft.com/downloads/details.aspx?familyid=998164B7-4B8C -468B-8D39-F242633C8838 -
Microsoft Security Update for Windows Server 2003 (KB981332)
http://www.microsoft.com/downloads/details.aspx?familyid=72754E1B-3D09 -4B9D-8794-689C45A37F66 -
Microsoft Security Update for Windows Server 2003 x64 Edition (KB981332)
http://www.microsoft.com/downloads/details.aspx?familyid=72C3013B-F72F -422B-8A89-2246DEA4B378 -
Microsoft Security Update for Windows Server 2008 (KB981332)
http://www.microsoft.com/downloads/details.aspx?familyid=527D6376-EFC9 -436B-835B-219D38BB28F0 -
Microsoft Security Update for Windows Server 2008 R2 for Itanium-based Systems (KB981332)
http://www.microsoft.com/downloads/details.aspx?familyid=8174463C-5C5E -4095-90C8-FD1E898D4BA5 -
Microsoft Security Update for Windows Server 2008 R2 x64 Edition (KB981332)
http://www.microsoft.com/downloads/details.aspx?familyid=C4039D40-A0C7 -4183-AB50-04F690D1C5DC -
Microsoft Security Update for Windows Server 2008 x64 Edition (KB981332)
http://www.microsoft.com/downloads/details.aspx?familyid=0C384DBC-21B7 -4CBC-B68F-CED971D9B791 -
Microsoft Security Update for Windows Vista (KB981332)
http://www.microsoft.com/downloads/details.aspx?familyid=F2A37DBF-4A95 -4E8D-A474-ECACD9AEE690 -
Microsoft Security Update for Windows Vista for x64-based Systems (KB981332)
http://www.microsoft.com/downloads/details.aspx?familyid=79093796-4EA9 -4C6C-92CC-3FD63C5DB918 -
Microsoft Security Update for Windows XP (KB981332)
http://www.microsoft.com/downloads/details.aspx?familyid=BA7EF6E5-80BA -4281-A611-6E5BE008C1B4 -
Microsoft Security Update for Windows XP x64 Edition (KB981332)
http://www.microsoft.com/downloads/details.aspx?familyid=153FD9C1-0F8E -4492-87D1-F0381E7FEB23
Microsoft VBScript 5.1
-
Microsoft Security Update for Windows 2000 (KB981350)
http://www.microsoft.com/downloads/details.aspx?familyid=421BE318-F217 -4D12-B7A5-833093189073
Microsoft VBScript 5.7
-
Microsoft Security Update for Windows 2000 (KB981349)
http://www.microsoft.com/downloads/details.aspx?familyid=D5FC47A4-CECB -4817-AAFB-45F335061BE3 -
Microsoft Security Update for Windows Server 2003 (KB981349)
http://www.microsoft.com/downloads/details.aspx?familyid=A142A553-85FC -40E0-9426-8D58F6A4333C -
Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB981349)
http://www.microsoft.com/downloads/details.aspx?familyid=7D542AC6-8A5B -4DD7-8688-2B5FEB563636 -
Microsoft Security Update for Windows Server 2003 x64 Edition (KB981349)
http://www.microsoft.com/downloads/details.aspx?familyid=A489B4E3-78D2 -411B-B27C-5987B8FC91D1 -
Microsoft Security Update for Windows Server 2008 (KB981349)
http://www.microsoft.com/downloads/details.aspx?familyid=DBE89813-0A45 -463B-928C-1E58F7BB596A -
Microsoft Security Update for Windows Server 2008 for Itanium-based Systems (KB981349)
http://www.microsoft.com/downloads/details.aspx?familyid=84C5AAAE-9417 -42A1-834F-22C1AD46A12F -
Microsoft Security Update for Windows Server 2008 x64 Edition (KB981349)
http://www.microsoft.com/downloads/details.aspx?familyid=9DB62357-557D -40CD-9826-B7BAA6C9DE65 -
Microsoft Security Update for Windows Vista (KB981349)
http://www.microsoft.com/downloads/details.aspx?familyid=EE5C42C6-16BB -48BF-95C2-C188BB17D04B -
Microsoft Security Update for Windows Vista for x64-based Systems (KB981349)
http://www.microsoft.com/downloads/details.aspx?familyid=EA5C5E9C-0ECD -47BC-912D-5ADC00D1AA21 -
Microsoft Security Update for Windows XP (KB981349)
http://www.microsoft.com/downloads/details.aspx?familyid=CB21D276-65E9 -4C8F-96E3-CF6DC36D0133 -
Microsoft Security Update for Windows XP x64 Edition (KB981349)
http://www.microsoft.com/downloads/details.aspx?familyid=D7E8B930-8708 -4F0B-B22B-961C2CBC2673
Microsoft VBScript 5.6
-
Microsoft Security Update for Windows 2000 (KB981350)
http://www.microsoft.com/downloads/details.aspx?familyid=421BE318-F217 -4D12-B7A5-833093189073 -
Microsoft Security Update for Windows Server 2003 (KB981350)
http://www.microsoft.com/downloads/details.aspx?familyid=28B035B8-D56E -4E93-B811-9A82CF1D4BA9 -
Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB981350)
http://www.microsoft.com/downloads/details.aspx?familyid=9A8BEE82-5F7F -490E-A1EB-481F6D4FC4F5 -
Microsoft Security Update for Windows Server 2003 x64 Edition (KB981350)
http://www.microsoft.com/downloads/details.aspx?familyid=339DDF48-8949 -4857-9EF6-1DDCC7C5F8B8 -
Microsoft Security Update for Windows XP (KB981350)
http://www.microsoft.com/downloads/details.aspx?familyid=AA8FF157-A7B3 -4787-80C9-5BC453F0F1C9 -
Microsoft Security Update for Windows XP x64 Edition (KB981350)
http://www.microsoft.com/downloads/details.aspx?familyid=896C738D-4058 -440F-8D4F-16C678610CD1
References
Microsoft VBScript 'winhlp32.exe' 'MsgBox()' Remote Code Execution Vulnerability
References:
References:
- Investigating a new win32hlp and Internet Explorer issue (Microsoft Security Response Center)
- isec-0027-msgbox-helpfile-ie.txt (Maurycy Prodeus)
- Microsoft Homepage (Microsoft)
- ASA-2010-095 MS10-022 Vulnerability in VBScript Could Allow Remote Code Executio (Avaya)
- Microsoft Security Advisory (981169) Vulnerability in VBScript Could Allow Remot (Microsoft)
- Microsoft Security Bulletin MS10-022 (Microsoft)
- Vulnerability Note VU#612021 Internet Explorer VBScript Windows Help arbitrary c (US-CERT)