NCP Secure Entry Client DLL Loading Arbitrary Code Execution Vulnerabilities
BID:43179
Info
NCP Secure Entry Client DLL Loading Arbitrary Code Execution Vulnerabilities
| Bugtraq ID: | 43179 |
| Class: | Design Error |
| CVE: | |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 13 2010 12:00AM |
| Updated: | Sep 27 2010 08:00PM |
| Credit: | Anastasios Monachos |
| Vulnerable: |
NCP Network Communication Secure Entry Client 9.23 build 17 NCP Network Communication Secure Client 8.11 Build 146 |
| Not Vulnerable: |
NCP Network Communication Secure Entry Client 9.23 build 18 NCP Network Communication Secure Enterprise Client 9.21 build 68 NCP Network Communication Secure Client Juniper Edition 9.23 build 18 |
Discussion
NCP Secure Entry Client DLL Loading Arbitrary Code Execution Vulnerabilities
NCP Secure Entry Client is prone to multiple vulnerabilities that let attackers execute arbitrary code.
An attacker can exploit these issues by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
NCP Secure Entry Client 9.23 Build 17 is vulnerable; other versions may also be affected.
NCP Secure Entry Client is prone to multiple vulnerabilities that let attackers execute arbitrary code.
An attacker can exploit these issues by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
NCP Secure Entry Client 9.23 Build 17 is vulnerable; other versions may also be affected.
Exploit / POC
NCP Secure Entry Client DLL Loading Arbitrary Code Execution Vulnerabilities
Attackers must entice an unsuspecting user to open a file on a remote WebDAV or SMB share to exploit these issues.
A general exploit technique has been documented by TheLeader and H.D. Moore for the Metasploit Project; please see the references for more information.
Attackers must entice an unsuspecting user to open a file on a remote WebDAV or SMB share to exploit these issues.
A general exploit technique has been documented by TheLeader and H.D. Moore for the Metasploit Project; please see the references for more information.
Solution / Fix
NCP Secure Entry Client DLL Loading Arbitrary Code Execution Vulnerabilities
Solution:
Updates are available; please see the references for more information.
Solution:
Updates are available; please see the references for more information.
References
NCP Secure Entry Client DLL Loading Arbitrary Code Execution Vulnerabilities
References:
References:
- Application DLL Load Hijacking (HD Moore)
- Exploiting DLL Hijacking Flaws (hdm)
- Microsoft Security Advisory 2269637 Released (Microsoft)
- More information about the DLL Preloading remote attack vector (Microsoft)
- NCP_Client_Vulnerability_Statement (NCP Network Communication)
- Vendor Homepage (NCP Network Communication)
- Microsoft Security Advisory (2269637) (Microsoft)