One Article Review

Accueil - L'article:
Source CVE.webp CVE Liste
Identifiant 3835547
Date de publication 2021-12-20 22:15:07 (vue: 2021-12-21 00:06:26)
Titre CVE-2021-43844
Texte MSEdgeRedirect is a tool to redirect news, search, widgets, weather, and more to a user's default browser. MSEdgeRedirect versions before 0.5.0.1 are vulnerable to Remote Code Execution via specifically crafted URLs. This vulnerability requires user interaction and the acceptance of a prompt. With how MSEdgeRedirect is coded, parameters are impossible to pass to any launched file. However, there are two possible scenarios in which an attacker can do more than a minor annoyance. In Scenario 1 (confirmed), a user visits an attacker controlled webpage; the user is prompted with, and downloads, an executable payload; the user is prompted with, and accepts, the aforementioned crafted URL prompt; and RCE executes the payload the user previously downloaded, if the download path is successfully guessed. In Scenario 2 (not yet confirmed), a user visits an attacked controlled webpage; the user is prompted with, and accepts, the aforementioned crafted URL prompt; and a payload on a remote, attacker controlled, SMB server is executed. The issue was found in the _DecodeAndRun() function, in which I incorrectly assumed _WinAPI_UrlIs() would only accept web resources. Unfortunately, file:/// passes the default _WinAPI_UrlIs check(). File paths are now directly checked for and must fail. There is no currently known exploitation of this vulnerability in the wild. A patched version, 0.5.0.1, has been released that checks for and denies these crafted URLs. There are no workarounds for this issue. Users are advised not to accept any unexpected prompts from web pages.
Envoyé Oui
Condensat 2021 43844 accept acceptance accepts advised aforementioned annoyance any are assumed attacked attacker been before browser can check checked checks code coded confirmed controlled crafted currently cve decodeandrun default denies directly download downloaded downloads executable executed executes execution exploitation fail file file:/// found from function guessed has how however impossible incorrectly interaction issue known launched minor more msedgeredirect must news not now only pages parameters pass passes patched path paths payload payload; possible previously prompt prompt; prompted prompts rce redirect released remote requires resources scenario scenarios search server smb specifically successfully than these tool two unexpected unfortunately url urlis urls user users version versions visits vulnerability vulnerable weather web webpage; which widgets wild winapi workarounds would yet
Tags Tool Vulnerability
Stories
Notes
Move


L'article ne semble pas avoir été repris aprés sa publication.


L'article ne semble pas avoir été repris sur un précédent.
My email: