Microsoft Windows Shortcut Vulnerability
BID:970
Info
Microsoft Windows Shortcut Vulnerability
| Bugtraq ID: | 970 |
| Class: | Unknown |
| CVE: |
CVE-2000-0129 |
| Remote: | Yes |
| Local: | Yes |
| Published: | Feb 04 2000 12:00AM |
| Updated: | Jul 11 2009 01:56AM |
| Credit: | Discovered by USSR labs <[email protected]> and publicized in USSR Advisory USSR-20000032 released February 4, 2000. |
| Vulnerable: |
Microsoft Windows NT Workstation 4.0 Microsoft Windows NT Terminal Server 4.0 Microsoft Windows NT Server 4.0 Microsoft Windows NT Enterprise Server 4.0 Microsoft Windows NT 4.0 Microsoft Windows 98 Microsoft Windows 95 Microsoft Windows 2000 Terminal Services Microsoft Windows 2000 Server Microsoft Windows 2000 Professional Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Advanced Server Cat Soft Serv-U 2.5 b Cat Soft Serv-U 2.5 a Cat Soft Serv-U 2.5 |
| Not Vulnerable: | |
Discussion
Microsoft Windows Shortcut Vulnerability
The Windows API that handles shortcut navigation is susceptible to buffer overflow attacks. The API, "SHGetPathFromIDList" will parse a shortcut file (.lnk) to find the target file, directory or URL. A specifically malformed link will cause any program using the API to follow that shortcut to crash.
NOTE: While this vulnerability listing, as well as the exploit and the original USSR advisory only mention Serv-U FTP server, any Windows, Microsoft, or 3rd party program that uses the API could be vulnerable to this.
The Windows API that handles shortcut navigation is susceptible to buffer overflow attacks. The API, "SHGetPathFromIDList" will parse a shortcut file (.lnk) to find the target file, directory or URL. A specifically malformed link will cause any program using the API to follow that shortcut to crash.
NOTE: While this vulnerability listing, as well as the exploit and the original USSR advisory only mention Serv-U FTP server, any Windows, Microsoft, or 3rd party program that uses the API could be vulnerable to this.
Exploit / POC
Microsoft Windows Shortcut Vulnerability
dserv2.5b.exe:
Executable exploit for Serv-U FTP server
dserv25b.zip:
Source code for above exploit
link.bro:
Example of a malformed shortcut file.
dserv2.5b.exe:
Executable exploit for Serv-U FTP server
dserv25b.zip:
Source code for above exploit
link.bro:
Example of a malformed shortcut file.
Solution / Fix
Microsoft Windows Shortcut Vulnerability
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
CatSoft has claimed that the next release of Serv-U will not rely on the API to follow shortcuts.
Solution:
Currently the SecurityFocus staff are not aware of any vendor supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: [email protected].
CatSoft has claimed that the next release of Serv-U will not rely on the API to follow shortcuts.
References
Microsoft Windows Shortcut Vulnerability
References:
References: