Windows Search Lets Remote Users Execute Scripting Code to Obtain Information
|
|
SecurityTracker Alert ID: 1022353 |
|
SecurityTracker URL: http://securitytracker.com/id/1022353
|
|
CVE Reference:
CVE-2009-0239
(Links to External Site)
|
Date: Jun 9 2009
|
Impact:
Disclosure of system information, Disclosure of user information
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): 4.0
|
Description:
A vulnerability was reported in Windows Search. A remote user can obtain potentially sensitive information from the target user's system.
A remote user can create a specially crafted file that, when processed by Windows Search on the target user's system, will execute arbitrary scripting code. This can be exploited to access information on the target user's system.
The target user must perform a search that returns the file as the first result for script execution to occur.
Yair Amit of IBM Rational Application Security reported this vulnerability.
|
Impact:
A remote user can obtain potentially sensitive information from the target user's system.
|
Solution:
The vendor has issued the following fixes:
Windows XP Service Pack 2 and Windows XP Service Pack 3, Windows Search 4.0:
http://www.microsoft.com/downloads/details.aspx?familyid=759f22cb-ea7f-49dd-a200-19cb83fffd8d
Windows XP Professional x64 Edition Service Pack 2, Windows Search 4.0:
http://www.microsoft.com/downloads/details.aspx?familyid=50c56dd6-c34d-4632-a779-8bcf8fdb341b
Windows Server 2003 Service Pack 2, Windows Search 4.0:
http://www.microsoft.com/downloads/details.aspx?familyid=e72ef31f-5161-4fe6-8ed3-6206e02cef31
Windows Server 2003 x64 Edition Service Pack 2, Windows Search 4.0:
http://www.microsoft.com/downloads/details.aspx?familyid=7ffc3680-f9bf-423b-96a7-102f4cc9c240
A restart is required.
The Microsoft advisory is available at:
http://www.microsoft.com/technet/security/bulletin/ms09-023.mspx
|
Vendor URL: www.microsoft.com/technet/security/bulletin/ms09-023.mspx (Links to External Site)
|
Cause:
Access control error
|
Underlying OS:
Windows (2003), Windows (XP)
|
|
Message History:
None.
|
Source Message Contents
|
Date: Tue, 9 Jun 2009 14:14:09 -0400
Subject: http://www.microsoft.com/technet/security/bulletin/ms09-023.mspx
|
Microsoft Security Bulletin MS09-023 - Moderate: Vulnerability in Windows Search Could Allow Information Disclosure (963093)
CVE-2009-0239
|
|