Multiple VNC Products For Windows Win32 Messaging API Vulnerability
BID:5530
Info
Multiple VNC Products For Windows Win32 Messaging API Vulnerability
| Bugtraq ID: | 5530 |
| Class: | Design Error |
| CVE: |
CVE-2002-0971 |
| Remote: | No |
| Local: | Yes |
| Published: | Aug 21 2002 12:00AM |
| Updated: | Jul 11 2009 03:56PM |
| Credit: | Published by Chris Bellers <[email protected]>. |
| Vulnerable: |
Tridia TridiaVNC 1.5.4 Tridia TridiaVNC 1.5.2 Tridia TridiaVNC 1.5.1 Tridia TridiaVNC 1.5 TightVNC TightVNC 1.2.5 TightVNC TightVNC 1.2.1 TightVNC TightVNC 1.2 .0 Avaya Labs Libsafe 1.2.4 Avaya Labs Libsafe 1.2.3 Avaya Labs Libsafe 1.2.2 AT&T WinVNC Server 3.3.3 R9 AT&T WinVNC Server 3.3.3 r7 AT&T WinVNC 3.3 x |
| Not Vulnerable: | |
Discussion
Multiple VNC Products For Windows Win32 Messaging API Vulnerability
Virtual Network Computing, or VNC, is a system which provides remote access to a desktop environment. A vulnerability has been reported in a number of VNC products when used on Microsoft Windows based systems.
Vulnerable VNC products provide graphical user interface elements which run with privileges. A local user with lower privileges may send arbitrary Win32 messages to the privileged process, possibly executing arbitrary code as the vulnerable process.
This general class of vulnerabilities has been documented as BID 5408.
Virtual Network Computing, or VNC, is a system which provides remote access to a desktop environment. A vulnerability has been reported in a number of VNC products when used on Microsoft Windows based systems.
Vulnerable VNC products provide graphical user interface elements which run with privileges. A local user with lower privileges may send arbitrary Win32 messages to the privileged process, possibly executing arbitrary code as the vulnerable process.
This general class of vulnerabilities has been documented as BID 5408.
Exploit / POC
Multiple VNC Products For Windows Win32 Messaging API Vulnerability
A tool for exploiting this class of vulnerability has been published by Chris Paget <[email protected]>:
http://security.tombom.co.uk/shatter.zip
A tool for exploiting this class of vulnerability has been published by Chris Paget <[email protected]>:
http://security.tombom.co.uk/shatter.zip
Solution / Fix
Multiple VNC Products For Windows Win32 Messaging API Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
Solution:
Currently we are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected] <mailto:[email protected]>.
References
Multiple VNC Products For Windows Win32 Messaging API Vulnerability
References:
References: