Microsoft Remote Desktop Connection Client DLL Loading Arbitrary Code Execution Vulnerability
BID:46678
Info
Microsoft Remote Desktop Connection Client DLL Loading Arbitrary Code Execution Vulnerability
| Bugtraq ID: | 46678 |
| Class: | Design Error |
| CVE: |
CVE-2011-0029 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 08 2011 12:00AM |
| Updated: | Mar 09 2011 05:57PM |
| Credit: | Eyal Gruner of Versafe Anti Fraud |
| Vulnerable: |
Microsoft Remote Desktop Connection Multilingual UI 6.0 Microsoft RDP 7.0 Microsoft RDP 6.1 Microsoft RDP 6.0 Microsoft RDP 5.2 Avaya Messaging Application Server 5.2 Avaya Messaging Application Server 5 Avaya Messaging Application Server 4 Avaya Meeting Exchange - Webportal 0 Avaya Meeting Exchange - Web Conferencing Server 0 Avaya Meeting Exchange - Streaming Server 0 Avaya Meeting Exchange - Recording Server 0 Avaya Meeting Exchange - Client Registration Server 0 Avaya Conferencing Standard Edition 6.0 Avaya Communication Server 1000 Telephony Manager 4.0 Avaya Communication Server 1000 Telephony Manager 3.0 Avaya CallPilot 5.0 Avaya CallPilot 4.0 |
| Not Vulnerable: | |
Discussion
Microsoft Remote Desktop Connection Client DLL Loading Arbitrary Code Execution Vulnerability
Microsoft Remote Desktop Connection client is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
NOTE: This issue may be related to BID 42853 (Microsoft Remote Desktop Protocol 'ieframe.dll' DLL Loading Arbitrary Code Execution Vulnerability).
Microsoft Remote Desktop Connection client is prone to a vulnerability that lets attackers execute arbitrary code.
An attacker can exploit this issue by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.
NOTE: This issue may be related to BID 42853 (Microsoft Remote Desktop Protocol 'ieframe.dll' DLL Loading Arbitrary Code Execution Vulnerability).
Exploit / POC
Microsoft Remote Desktop Connection Client DLL Loading Arbitrary Code Execution Vulnerability
A general exploit technique has been documented by TheLeader and H.D. Moore for the Metasploit Project; please see the references for more information.
A general exploit technique has been documented by TheLeader and H.D. Moore for the Metasploit Project; please see the references for more information.
Solution / Fix
Microsoft Remote Desktop Connection Client DLL Loading Arbitrary Code Execution Vulnerability
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft RDP 6.0
Microsoft RDP 7.0
Microsoft Remote Desktop Connection Multilingual UI 6.0
Microsoft RDP 5.2
Microsoft RDP 6.1
Solution:
The vendor has released an advisory and updates. Please see the references for details.
Microsoft RDP 6.0
-
Microsoft WindowsServer2003-KB2481109-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=641D5D12-0790 -4551-831A-E78FEBAD17A7 -
Microsoft WindowsServer2003.WindowsXP-KB2481109-x64-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=6D4539EF-4A05 -4C7D-9489-436F7B7A3EBE
Microsoft RDP 7.0
-
Microsoft Windows6.1-KB2483614-ia64.msu
http://www.microsoft.com/downloads/details.aspx?familyid=C29B6487-78F0 -421C-810C-C5E45D6A2352 -
Microsoft Windows6.1-KB2483614-x86.msu
http://www.microsoft.com/downloads/details.aspx?familyid=0768A5F4-DA28 -4B2E-8AFF-D68F890DF3E6 -
Microsoft Windows6.0-KB2483614-x64.msu
http://www.microsoft.com/downloads/details.aspx?familyid=8025482B-F58F -4F5A-A133-5563C65B21F6 -
Microsoft WindowsXP-KB2483614-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=6A01992E-C9A1 -4DC9-A3EF-7410B81F17E6 -
Microsoft Windows6.1-KB2483614-x64.msu
http://www.microsoft.com/downloads/details.aspx?familyid=935ADB10-1E7E -4501-B543-8247B88F6D18 -
Microsoft Windows6.0-KB2483614-x86.msu
http://www.microsoft.com/downloads/details.aspx?familyid=3C30F67E-7C31 -4553-BA3E-E056DF1BF8EB
Microsoft Remote Desktop Connection Multilingual UI 6.0
-
Microsoft WindowsServer2003-KB2483619-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=6FEC0D06-042D -4E55-9843-009EDD7D26CE
Microsoft RDP 5.2
-
Microsoft WindowsXP-KB2483618-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=1AED6080-FEAB -4B5E-9D26-6A3F4B92434D
Microsoft RDP 6.1
-
Microsoft Windows6.0-KB2481109-x64.msu
http://www.microsoft.com/downloads/details.aspx?familyid=5735BED6-0E3D -46A4-85D0-14EC34A82EDD -
Microsoft WindowsXP-KB2481109-x86-ENU.exe
http://www.microsoft.com/downloads/details.aspx?familyid=D67E4D8C-AEB9 -45E6-9555-7456C5540475 -
Microsoft Windows6.0-KB2481109-x86.msu
http://www.microsoft.com/downloads/details.aspx?familyid=E3EA7690-386B -4CDF-889F-B3914921C56F -
Microsoft Windows6.0-KB2481109-ia64.msu
http://www.microsoft.com/downloads/details.aspx?familyid=25DA7E00-745D -4D98-9DD8-52A8A4340404
References
Microsoft Remote Desktop Connection Client DLL Loading Arbitrary Code Execution Vulnerability
References:
References:
- Application DLL Load Hijacking (HD Moore)
- Exploiting DLL Hijacking Flaws (hdm)
- Microsoft Homepage (Microsoft)
- Microsoft Security Advisory 2269637 Released (Microsoft)
- More information about the DLL Preloading remote attack vector (Microsoft)
- Microsoft Security Advisory (2269637) (Microsoft)
- Microsoft Security Bulletin MS11-017 (Microsoft)
- MS11-017 Vulnerability in Remote Desktop Client Allow Remote Code Execution (Avaya)