[PCWorks] Windows Explorer Saved Search Vulnerability in Vista & Server 2008

  • From: "Clint Hamilton-PCWorks Admin" <PCWorks@xxxxxxxxxxxxxxxxxxxxxxxx>
  • To: "PCWorks@xxxxxxxxxxxxx" <pcworks@xxxxxxxxxxxxx>
  • Date: Tue, 8 Jul 2008 13:38:53 -0500

TITLE:
Microsoft Windows Explorer Saved Search Vulnerability

SECUNIA ADVISORY ID:
SA30953

VERIFY ADVISORY:
http://secunia.com/advisories/30953/

CRITICAL:
Moderately critical

IMPACT:
System access

WHERE:
From remote

OPERATING SYSTEM:
Microsoft Windows Server 2008
http://secunia.com/product/18255/
Microsoft Windows Vista
http://secunia.com/product/13223/

DESCRIPTION:
A vulnerability has been reported in Microsoft Windows, which 
can be
exploited by malicious people to compromise a user's system.

The vulnerability is caused due to an error in Windows Explorer
during the parsing of saved-search (.search-ms) files when 
saving
them. This can be exploited to execute arbitrary code by 
tricking a
user into opening and saving a specially crafted saved-search 
file.

SOLUTION:
Apply patches.

Windows Vista (optionally with SP1):
http://www.microsoft.com/downloads/details.aspx?familyid=06739ca6-7368-4acb-bb67-7e8146071a29

Windows Vista x64 Edition (optionally with SP1):
http://www.microsoft.com/downloads/details.aspx?familyid=74ea0893-7c2f-4fad-ad27-588ad953b046

Windows Server 2008 for 32-bit Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=189a4170-b495-4904-9cbd-209e7494d303

Windows Server 2008 for x64-based Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=85d8701d-f8c7-4079-8a21-a3a9d5ba71ce

Windows Server 2008 for Itanium-based Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=b30ee4f0-850f-4ff3-86a4-663603a0a802

PROVIDED AND/OR DISCOVERED BY:
Reported by the vendor.

ORIGINAL ADVISORY:
MS08-038 (KB950582):
http://www.microsoft.com/technet/security/Bulletin/MS08-038.mspx


=========================
The list's FAQ's can be seen by sending an email to 
PCWorks-request@xxxxxxxxxxxxx with FAQ in the subject line.

To unsubscribe, subscribe, set Digest or Vacation to on or off, go to 
//www.freelists.org/list/pcworks .  You can also send an email to 
PCWorks-request@xxxxxxxxxxxxx with Unsubscribe in the subject line.  Your 
member list settings can be found at 
//www.freelists.org/cgi-bin/lsg2.cgi/l=pcworks .  Once logged in, you have 
access to numerous other email options.  

The list archives are located at //www.freelists.org/archives/pcworks/ .  
All email posted to the list will be placed there in the event anyone needs to 
look for previous posts.

Other related posts:

  • » [PCWorks] Windows Explorer Saved Search Vulnerability in Vista & Server 2008