Microsoft Windows User Shell Buffer Overflow Vulnerability
BID:4248
Info
Microsoft Windows User Shell Buffer Overflow Vulnerability
| Bugtraq ID: | 4248 |
| Class: | Boundary Condition Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 07 2002 12:00AM |
| Updated: | Mar 07 2002 12:00AM |
| Credit: | Vulnerability discovery credited to Eeye Digital Security. |
| Vulnerable: |
Microsoft Windows NT Workstation 4.0 SP6a Microsoft Windows NT Workstation 4.0 SP6 Microsoft Windows NT Workstation 4.0 SP5 Microsoft Windows NT Workstation 4.0 SP4 Microsoft Windows NT Workstation 4.0 SP3 Microsoft Windows NT Workstation 4.0 SP2 Microsoft Windows NT Workstation 4.0 SP1 Microsoft Windows NT Workstation 4.0 Microsoft Windows NT Terminal Server 4.0 SP6 Microsoft Windows NT Terminal Server 4.0 SP5 Microsoft Windows NT Terminal Server 4.0 SP4 Microsoft Windows NT Terminal Server 4.0 SP3 Microsoft Windows NT Terminal Server 4.0 SP2 Microsoft Windows NT Terminal Server 4.0 SP1 Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT Server 4.0 SP6a Microsoft Windows NT Server 4.0 SP6 Microsoft Windows NT Server 4.0 SP5 Microsoft Windows NT Server 4.0 SP4 Microsoft Windows NT Server 4.0 SP3 Microsoft Windows NT Server 4.0 SP2 Microsoft Windows NT Server 4.0 SP1 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 SP6a Microsoft Windows NT Enterprise Server 4.0 SP6 Microsoft Windows NT Enterprise Server 4.0 SP5 Microsoft Windows NT Enterprise Server 4.0 SP4 Microsoft Windows NT Enterprise Server 4.0 SP3 Microsoft Windows NT Enterprise Server 4.0 SP2 Microsoft Windows NT Enterprise Server 4.0 SP1 Microsoft Windows NT Enterprise Server 4.0 Microsoft Windows 98SE Microsoft Windows 98 SP1 Microsoft Windows 98 Microsoft Windows 2000 Server SP2 Microsoft Windows 2000 Server SP1 Microsoft Windows 2000 Server Microsoft Windows 2000 Professional SP2 Microsoft Windows 2000 Professional SP1 Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server SP2 Microsoft Windows 2000 Datacenter Server SP1 Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server SP2 Microsoft Windows 2000 Advanced Server SP1 Microsoft Windows 2000 Advanced Server |
| Not Vulnerable: | |
Discussion
Microsoft Windows User Shell Buffer Overflow Vulnerability
A buffer overflow has been discovered in the Windows user shell. The condition exists in the component of the user shell responsible for locating programs that are 'missing' to the system. 'missing' applications are those which have been registered as installed programs, but have been deleted or improperly uninstalled.
Under extreme circumstances, this vulnerability may be remotely exploitable. This may be the case if an application has registered itself as an URL handler and is improperly uninstalled.
The overflow condition may be triggered in an exploitable manner if the URL handler is invoked when a specially constructed link is clicked on by a user visiting a malicious website (or reading HTML email).
When searching for the 'missing' application, the data in the URL may overwrite an activation record in the stack of the shell process.
If an attacker is aware of the registered URL-handler and can anticipate the application being 'missing', an URL containing a replacement return address and shellcode may be constructed. If a victim were to click on the link (and if the attempt is successful), arbitrary code may be executed on the client system within the security context of the user.
A buffer overflow has been discovered in the Windows user shell. The condition exists in the component of the user shell responsible for locating programs that are 'missing' to the system. 'missing' applications are those which have been registered as installed programs, but have been deleted or improperly uninstalled.
Under extreme circumstances, this vulnerability may be remotely exploitable. This may be the case if an application has registered itself as an URL handler and is improperly uninstalled.
The overflow condition may be triggered in an exploitable manner if the URL handler is invoked when a specially constructed link is clicked on by a user visiting a malicious website (or reading HTML email).
When searching for the 'missing' application, the data in the URL may overwrite an activation record in the stack of the shell process.
If an attacker is aware of the registered URL-handler and can anticipate the application being 'missing', an URL containing a replacement return address and shellcode may be constructed. If a victim were to click on the link (and if the attempt is successful), arbitrary code may be executed on the client system within the security context of the user.
References
Microsoft Windows User Shell Buffer Overflow Vulnerability
References:
References: