CERT-In Vulnerability Note
CIVN-2010-0169
Microsoft Windows Shell shortcut handling remote code execution vulnerability
Original Issue Date:July 19, 2010
Updated: August 09, 2010
Severity Rating: HIGH
Systems Affected
- Windows XP Service Pack 3
- Windows XP Professional x64 Edition SP 2
- Windows Server 2003 SP 2
- Windows Server 2003 x64 Edition SP 2
- Windows Server 2003 with SP2 for Itanium-based Systems
- Windows Vista SP 1 and SP 2
- Windows Vista x64 Edition SP 1 and SP 2
- Windows Server 2008 for 32-bit Systems and SP 2
- Windows Server 2008 for x64-based Systems and SP 2
- Windows Server 2008 for Itanium-based Systems and SP 2
- Windows 7 for 32-bit Systems
- Windows 7 for x64-based Systems
- Windows Server 2008 R2 for x64-based Systems
- Windows Server 2008 R2 for Itanium-based Systems
Overview
A remote code execution vulnerability has been reported in Windows Shell , that does not correctly validate specific parameters of the shortcut when attempting to load the icon of a shortcut.
Description
This issue is due to an error in the Windows Shell component when parsing shortcuts (.LNK, .PIF files), which could allow attackers to automatically execute a malicious binary by tricking a user into opening in Windows Explorer a removable drive (e.g. USB) or browsing a remote network or WebDAV share containing a specially crafted shortcut file.
Successful exploits allows the remote attacker to execute arbitrary code in the context of the logged-in user.
Note: The vulnerability has been actively exploited in targeted attacks.
Workaround
- Disable the displaying of icons for shortcuts
- Disable the WebClient service
- Disable AutoRun
- Block outgoing SMB traffic
- Block the download of LNK and PIF files from the Internet
Note : A new Fix It tool
which allows administrators and users to more easily deploy the workaround.
Note : For detailed steps and impact of applying these workarounds refer to Microsoft Security Advisory 2286198 .
Solution
Apply appropriate patches as mentioned in Microsoft security Bulletin
MS10-046
Vendor Information
Microsoft
http://www.microsoft.com/technet/security/Bulletin/MS10-046.mspx
http://www.microsoft.com/technet/security/advisory/2286198.mspx
References
Microsoft
http://support.microsoft.com/kb/2286198
http://www.microsoft.com/technet/security/advisory/2286198.mspx
http://blogs.technet.com/b/msrc/archive/2010/07/16/security-advisory-2286198-released.aspx
http://support.microsoft.com/kb/967715
VUPEN
http://www.vupen.com/english/advisories/2010/1836
US-CERT
http://www.kb.cert.org/vuls/id/940193
Securityfocus
http://www.securityfocus.com/bid/41732
VIrusBlokADa
http://www.anti-virus.by/en/tempo.shtml
CVE Name
CVE-2010-2568
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|