CERT-In Vulnerability Note
CIVN-2015-0276
Microsoft Windows Journal Remote Code Execution Vulnerability
Original Issue Date:November 12, 2015
Severity Rating: HIGH
Software Affected
- Windows Vista Service Pack 2
- Windows Vista x64 Edition Service Pack 2
- Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Server 2008 for x64-based Systems Service Pack 2
- Windows 7 for 32-bit Systems Service Pack 1
- Windows 7 for x64-based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
Overview
A vulnerability has been reported in Microsoft Journal which could be exploited by a remote attacker to execute arbitrary code on the target system.
Description
A remote code execution vulnerability exist in Microsoft windows Journal due to improper parsing of journal files. A remote attacker could exploit these vulnerabilities by sending a specially crafted Journal file to the user and by convincing the user to open the file.
Successful exploitation of these vulnerabilities could allow a remote attacker to execute arbitrary code with the privileges of the user.
Workaround
- Do not open suspicious file attachments
- Remove the .jnt file type association
- Remove Windows Journal by disabling the Windows feature that installs it
- Deny access to Journal.exe
Solution
Apply appropriate patch as mentioned in Microsoft Security Bulletin
MS15-114
Vendor Information
Microsoft
https://technet.microsoft.com/en-us/library/security/ms15-114.aspx
References
Microsoft
https://technet.microsoft.com/en-us/library/security/ms15-114.aspx
SecurityTracker
http://securitytracker.com/id/1034110
CISCO
http://tools.cisco.com/security/center/viewAlert.x?alertId=41847
CVE Name
CVE-2015-6097
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|