[NT] Microsoft Interactive Training .cbo Overflow
- From: SecuriTeam <support@xxxxxxxxxxxxxx>
- Date: 20 Feb 2007 13:56:31 +0200
The following security advisory is sent to the securiteam mailing list, and can be found at the SecuriTeam web site: http://www.securiteam.com
- - promotion
The SecuriTeam alerts list - Free, Accurate, Independent.
Get your security news from a reliable source.
http://www.securiteam.com/mailinglist.html
- - - - - - - - -
Microsoft Interactive Training .cbo Overflow
------------------------------------------------------------------------
SUMMARY
A vulnerability in Microsoft's Interactive Training (cbo files) allows
remote attackers to supply a user a seamlessly harmless files which in
turn can be used to execute arbitrary code via overflowing of a buffer.
DETAILS
When thinking about buffer overflow vulnerabilities, a file can sometimes
be as harmful as a packet. Even though past security issues have taught us
that it is unwise to use a string from a file/packet without first
checking its length, this is what happened here.
MS Interactive Training will open a file with a .cbo extension and read in
the Syllabus details.
Through the creation of a corrupt file, with a long Syllabus string it is
possible to gain control of EIP and execute arbitrary code.
[Microsoft Interactive Training]
Topic=Using the Start Menu
Lesson=Getting Started with Windows XP Professional
User=DEFAULT
Syllabus=<long string>
Database=C:\Documents and Settings\All Users\Application Data\SBSI\ORUN\
SerialID=00000000
Exploitation:
Remote exploitation through Internet Explorer can be obtained through
hosting a malicious .cbo file which will be downloaded and opened
automatically.
Solutions:
Install the vendor supplied patch:
<http://www.microsoft.com/technet/security/bulletin/MS07-005.mspx>
http://www.microsoft.com/technet/security/bulletin/MS07-005.mspx
ADDITIONAL INFORMATION
The information has been provided by
<mailto:brett.moore@xxxxxxxxxxxxxxxxxxxxxxx> Brett Moore.
The original article can be found at:
<http://www.security-assessment.com/files/advisories/MS_Interactive_Training_.cbo_Overflow_2.pdf> http://www.security-assessment.com/files/advisories/MS_Interactive_Training_.cbo_Overflow_2.pdf
========================================
This bulletin is sent to members of the SecuriTeam mailing list.
To unsubscribe from the list, send mail with an empty subject line and body to: list-unsubscribe@xxxxxxxxxxxxxx
In order to subscribe to the mailing list, simply forward this email to: list-subscribe@xxxxxxxxxxxxxx
====================
====================
DISCLAIMER:
The information in this bulletin is provided "AS IS" without warranty of any kind.
In no event shall we be liable for any damages whatsoever including direct, indirect, incidental, consequential, loss of business profits or special damages.
- Prev by Date: [NEWS] Multiple Vulnerabilities in Cisco Firewall Services Module (FWSM)
- Next by Date: [NT] Lizardtech DjVu Browser Plug-in Multiple Vulnerabilities
- Previous by thread: [NEWS] Multiple Vulnerabilities in Cisco Firewall Services Module (FWSM)
- Next by thread: [NT] Lizardtech DjVu Browser Plug-in Multiple Vulnerabilities
- Index(es):
Relevant Pages
- [NT] Ipswitch Multiple Vulnerabilities (IMail IMAP LIST Command DoS, Collaboration Suite SMTP Format
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Ipswitch Multiple Vulnerabilities
(IMail IMAP LIST Command DoS, ... Collaboration Suite SMTP Format String) ... Remote
exploitation of a denial of service vulnerability in Ipswitch ... (Securiteam) - [NT] Microsoft Windows Interactive Training Buffer Overflow (MS05-031)
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... Microsoft Interactive Training
is "an application included with some OEM ... versions of Windows XP that allows users
to receive multimedia training on ... and it will process .cbo files. ... (Securiteam) - [UNIX] TikiWiki PHP Code Evaluation Vulnerability
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... TikiWiki PHP Code Evaluation
Vulnerability ... ' - String delimiter ... (Securiteam) - [UNIX] MySQL Authentication Scheme Bypass
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... By submitting a carefully crafted
authentication packet, ... the user has specified a 'scrambled' string that is as long
... stack-based buffer 'buff' can be overflowed by a long 'scramble' string. ...
(Securiteam) - [NT] WebArchiveX Unsafe Methods Vulnerability
... The following security advisory is sent to the securiteam mailing list, and can be
found at the SecuriTeam web site: http://www.securiteam.com ... String userAgent,
... scripting' entry, but unfortunately has not changed the version number. ...
(Securiteam)