CERT-In Vulnerability Note
CIVN-2004-0055
Vulnerability in Compressed zipped Folders Could Allow Remote Code Execution
Original Issue Date:October 14, 2004
Severity Rating: HIGH
Systems Affected
- Microsoft Windows XP and Microsoft Windows XP Service Pack 1
- Microsoft Windows XP 64-Bit Edition Service Pack 1
- Microsoft Windows XP 64-Bit Edition Version 2003
- Microsoft Windows Server 2003
- Microsoft Windows Server 2003 64-Bit Edition
Overview
A vulnerability exists in Microsoft Windows the way it processes compressed zipped folder which can be exploited by a remote attacker to execute an arbitrary code on the affected system.
Impact
The remote attacker could execute the arbitrary code on the affected system possibly with administrator privileges by convincing the user to access a specially crafted .zip file.
Description
A remote code execution vulnerability exists in Compressed zipped Folders
which is caused due to a boundary error in handling compressed zipped folders. When a user opens malicious .zip file containing long file name greater than around 0x8000 bytes a stack-based buffer overflow occurs. An attacker who successfully exploited this vulnerability could take complete control of the affected system. However user intervention is required to exploit this vulnerability.
Workaround
- Remove the registration for Compressed zipped Folders
- Do Not Accept Zip Files from Untrusted Sources
Solution
Apply appropriate Security update as mentioned in Microsoft Security Bulletin
MS04-034
Vendor Information
Microsoft Corporation
Microsoft Security Bulletin MS04-034
References
Vulnerability Note VU#649374
http://www.kb.cert.org/vuls/id/649374
Secunia Advisory SA12805
http://secunia.com/advisories/12805/
Eye Digital Security
http://www.eeye.com/html/research/advisories/ AD20041012A.html
Neohapsis
http://archives.neohapsis.com/archives/ntbugtraq/ 2004-q4/0051.html
CVE Name
CAN-2004-0575
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|