The Active Network
ActiveWin Anonymous | Create a User | Reviews | News | Forums | Advertise | VBA in Excel | Users Online: 0  
 

neowin.net

Amazon.com

  *  

  Microsoft Windows "desktop.ini" Arbitrary File Execution Vulnerability
Time: 10:33 EST/15:33 GMT | News Source: E-Mail | Posted By: Byron Hinson

Roozbeh Afrasiabi has reported a vulnerability in Microsoft Windows, which can be exploited by malicious, local users to gain escalated privileges. The problem is that "desktop.ini" files may contain CLSID references to arbitrary executables in the "[.ShellClassInfo]" section. This can be exploited to execute arbitrary files with another user's privileges when the user browses a folder containing a malicious "desktop.ini" file.

Read Only Comments
Return to News
  Displaying 0 comments
  This is an archived static copy of ActiveWin.com.

Be the first to write a comment on this story!




 

  *  
  *   *
 
replica watches