ID: 3960
Date: 18/07/2010
Title: 3960 - Microsoft Security Advisory - Vulnerability in Windows Shell Could Allow Remote Code Execution
Platform level affected:Operating System
Specific operating systems components affected: 32-bit Windows
Remediation Summary:The manufacturer has reported a problem with this product but has yet to publish a solution. CPNI advise that additional care is exercised when using this product.
Vendors affected:Microsoft
Applications affected:Windows
Adversity source: Unknown
Attack Vector: Vulnerability exploitation
Virulence: Unknown
Warning Status: Active
Potential Damage: Remote execution/modification
Possible Duration: Unknown
Availability of fix: Future
Type of fix: Automated Patch
Source: Microsoft
Reliability of source: Trusted
Source URL: http://www.microsoft.com/technet/security/advisory/2286198.mspx
CVE: CVE-2010-2568
Abstract: Reports of limited, targeted attacks exploiting a vulnerability in Windows Shell, a component of Microsoft Windows
Microsoft Security Advisory (2286198)
Microsoft is investigating reports of limited, targeted attacks exploiting a vulnerability in Windows Shell, a component of Microsoft Windows. This advisory contains information about which versions of Windows are vulnerable as well as workarounds and mitigations for this issue.
The vulnerability exists because Windows incorrectly parses shortcuts in such a way that malicious code may be executed when the user clicks the displayed icon of a specially crafted shortcut. This vulnerability is most likely to be exploited through removable drives. For systems that have AutoPlay disabled, customers would need to manually browse to the root folder of the removable disk in order for the vulnerability to be exploited. For Windows 7 systems, AutoPlay functionality for removable disks is automatically disabled.
There are reports of targeted malware exploiting this vulnerability.
Further details and workarounds are available at: http://www.microsoft.com/technet/security/advisory/2286198.mspx
This advisory contains information released by the original author. Some of the information may have changed since it was released. If the issue affects you, it may be prudent to retrieve the advisory from the site of the original source to ensure that you receive the most current information concerning that problem. Reference to any specific commercial product, process, or service by trade name, trademark manufacturer, or otherwise, does not constitute or imply its endorsement, recommendation, or favouring by CPNI.
The views and opinions of authors expressed within this notice shall not be used for advertising or product endorsement purposes. CPNI shall not accept responsibility for any errors or omissions contained within this advisory. In particular, they shall not be liable for any loss or damage whatsoever, arising from or in connection with the usage of information contained within this advisory.
CSIRTUK is a member of the Forum of Incident Response and Security Teams (FIRST) and has contacts with other international Incident Response Teams (IRTs) in order to foster cooperation and coordination in incident prevention, to prompt rapid reaction to incidents, and to promote information sharing amongst its members and the community at large.
Sun, 18 Jul 2010 15:20:00 GMT
Domain affected: Technical