vendor:
Windows
by:
hyp3rlinx
8.8
CVSS
HIGH
URL Field Code Execution
N/A
CWE
Product Name: Windows
Affected Version From: 1.9.6
Affected Version To: 1.9.6
Patch Exists: NO
Related CWE: N/A
CPE: a:microsoft:windows
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2020
Microsoft Windows .Group File – Code Execution
Windows ".group" files are related to Contact files and suffer from unexpected code execution when clicking the "Contact Group Details" tab Website Go button. This happens if the website URL field points to an executable file. This is the same type of vulnerability affecting Windows .contact files that remains unfixed as of the time of this writing and has a metasploit module available.
Mitigation:
Microsoft has not released a patch for this vulnerability.