Windows Explorer Bug in Parsing Saved Search Files Lets Remote Users Execute Arbitrary Code
|
|
SecurityTracker Alert ID: 1020436
|
|
SecurityTracker URL: http://securitytracker.com/id?1020436
|
|
CVE Reference: CVE-2008-1435
(Links to External Site)
|
Date: Jul 8 2008
|
Impact: Execution of arbitrary code via network, User access via network
|
Fix Available: Yes
Vendor Confirmed: Yes
|
Advisory: Microsoft Security Bulletin
|
Version(s): Vista, Vista SP1, 2008
|
Description: A vulnerability was reported in Windows Explorer. A remote user can cause arbitrary code to be executed on the target user's system.
A remote user can create a specially crafted saved-search file file that, when opened by the target user via Windows Explorer, will
trigger a parsing error and execute arbitrary code on the target system. The code will run with the privileges of the target user.
Microsoft
Windows Vista and Windows Server 2008 are affected.
|
Impact: A remote user can create a file that, when loaded by the target user, will execute arbitrary code on the target user's system.
|
Solution: The vendor has issued the following fixes:
Windows Vista and Windows Vista Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=06739ca6-7368-4ac
b-bb67-7e8146071a29
Windows Vista x64 Edition and Windows Vista x64 Edition Service Pack 1:
http://www.microsoft.com/downloads/details.aspx?familyid=74ea0893-7c2f-4
fad-ad27-588ad953b046
Windows Server 2008 for 32-bit Systems*:
http://www.microsoft.com/downloads/details.aspx?familyid=189a4170-b495-4904-9cbd-209e7494d303
Wind
ows Server 2008 for x64-based Systems*:
http://www.microsoft.com/downloads/details.aspx?familyid=85d8701d-f8c7-4079-8a21-a3a9d5ba71ce
Windows
Server 2008 for Itanium-based Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=b30ee4f0-850f-4ff3-86a4-663603a0a802
*
= (core installation is affected).
A restart is required.
The Microsoft advisory is available at:
http://www.microsoft.com/technet/security/bulletin/ms08-038.msp
x
|
Vendor URL: www.microsoft.com/technet/security/Bulletin/MS08-038.mspx (Links to External Site)
|
Cause: Input validation error
|
Underlying OS: Windows (2008), Windows (Vista)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 8 Jul 2008 12:51:37 -0400
Subject: Microsoft Security Bulletin MS08-038 Important: Vulnerability in Windows Explorer Could Allow Remote Code Execution (950582)
|
http://www.microsoft.com/technet/security/bulletin/ms08-038.mspx
CVE-2008-0951
CVE-2008-1435
|
|