CERT-In Vulnerability Note
CIVN-2012-0108
Remote Code Execution Vulnerability in Microsoft Windows Briefcase
Original Issue Date:November 14, 2012
Severity Rating: HIGH
Systems Affected
- Windows XP SP 3
- Windows XP Professional x64 Edition SP 2
- Windows Server 2003 SP 2 and x64 Edition SP 2
- Windows Server 2003 with SP2 for Itanium-based Systems
- Windows Vista SP 2 and x64 Edition SP 2
- Windows Server 2008 for 32-bit Systems SP 2 and x64-based Systems SP 2
- Windows 7 for 32-bit Systems SP 1 and prior
- Windows 7 for x64-based Systems SP 1 and prior
- Windows Server 2008 R2 for x64-based Systems SP 1 and prior
- Windows 8 for 32-bit and 64-bit Systems
- Windows Server 2012
Overview
Multiple Remote Code Execution vulnerabilities have been reported in Microsoft Windows Briefcase which is a feature in Windows that synchronizes the contents of two folders. A remote attacker could exploit this vulnerability by convincing a user to open a specially crafted Briefcase in Windows Explorer. Successful exploitation of this vulnerability could allow a remote attacker to execute arbitrary code with the gained privileges of the affected system.
Description
1. Microsoft Windows Briefcase Integer Underflow Vulnerability
(
CVE-2012-1527
)
This vulnerability occurs due to an Integer underflow flaw in the Briefcase feature in Microsoft Windows, which could be exploited by a remote attacker if a user browses to a specially crafted briefcase in Windows Explorer. An attacker who successfully exploited this vulnerability could gain the user rights of the logged-on user and could take the complete control of an affected system.
2. Microsoft Windows Briefcase Integer Overflow Vulnerability
(
CVE-2012-1528
)
This vulnerability occurs due to an Integer overflow flaw in the Briefcase feature in Microsoft Windows, which could be exploited by a remote attacker if a user browses to a specially crafted briefcase in Windows Explorer. An attacker who successfully exploited this vulnerability could gain the user rights of the logged-on user and could take the complete control of an affected system.
Workaround
- Uninstall the Briefcase namespace shell extension.
Solution
Apply appropriate patches as mentioned in Microsoft Security Bulletin
MS12-072
Vendor Information
Microsoft
https://technet.microsoft.com/en-us/security/bulletin/ms12-072
References
SecurityFocus
http://www.securityfocus.com/bid/56424
Synmantec
http://www.symantec.com/security_response/vulnerability.jsp?bid=56424&om_rssid=sr-advisories
SecurityTracker
http://www.securitytracker.com/id/1027748
CVE Name
CVE-2012-1527
CVE-2012-1528
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|