vendor:
Windows
by:
John Page (aka hyp3rlinx)
5.5
CVSS
MEDIUM
Insufficient UI Warning Arbitrary Code Execution
264
CWE
Product Name: Windows
Affected Version From: Windows 7
Affected Version To: Windows 10
Patch Exists: Yes
Related CWE: CVE-2020-1464
CPE: o:microsoft:windows
Other Scripts:
N/A
Platforms Tested: Windows 7, Windows 8, Windows 10
2020
Microsoft .CONTACT File Insufficient UI Warning Arbitrary Code Execution
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The flaw is due to the processing of '.contact' files <c:Url> node param which takes an expected website value, however if an attacker references an executable file it will run that instead without warning instead of performing expected web navigation. Rename any executable file extension from '.exe' to '.co' and place it in a directory with a '.contact' file. When the '.contact' file is opened the executable will run without warning.
Mitigation:
Microsoft has released a patch to address this vulnerability. Users should apply the patch as soon as possible.