vendor:
ICQ
by:
Nine:Situations:Group::pyrokinesis
7.5
CVSS
HIGH
Remote Buffer Overflow
119
CWE
Product Name: ICQ
Affected Version From: ICQ 6.5
Affected Version To: Unknown
Patch Exists: NO
Related CWE: CVE-2009-1836
CPE: a:icq:icq:6.5
Metasploit:
https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2009-1126/, https://www.rapid7.com/db/vulnerabilities/linuxrpm-RHSA-2009-1095/, https://www.rapid7.com/db/vulnerabilities/mozilla-seamonkey-cve-2009-1836/, https://www.rapid7.com/db/vulnerabilities/mfsa2009-27-cve-2009-1836/, https://www.rapid7.com/db/vulnerabilities/gentoo-linux-cve-2009-1836/, https://www.rapid7.com/db/vulnerabilities/mozilla-thunderbird-cve-2009-1836/, https://www.rapid7.com/db/vulnerabilities/centos_linux-cve-2009-1836/, https://www.rapid7.com/db/vulnerabilities/suse-cve-2009-1836/
Platforms Tested: Windows
Unknown
ICQ 6.5 URL Search Hook/ICQToolBar.dll .URL file processing Windows Explorer remote buffer overflow poc
The vulnerability exists in the ICQ 6.5 URL Search Hook/ICQToolBar.dll .URL file processing in Windows Explorer. By placing a specially crafted .URL file on the desktop or in a network folder, an attacker can cause the explorer.exe process to exit with code 1282, resulting in a denial-of-service condition. This vulnerability can also affect Internet Explorer.
Mitigation:
Disable the shell extension or use shellexview by nirsoft to disable the ICQ 6.5 URL Search Hook/ICQToolBar.dll .URL file processing in Windows Explorer.