vendor:
KVIrc
by:
Nine:Situations:Group::strawdog
7.5
CVSS
HIGH
Command Line Parsing Vulnerability
94
CWE
Product Name: KVIrc
Affected Version From: 3.4.2 Shiny
Affected Version To: 3.4.2 Shiny
Patch Exists: Yes
Related CWE: CVE-2008-5183
CPE: a:kvirc:kvirc
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: IE8beta/WINxpsp3
2008
KVIrc 3.4.2 Shiny (uri handler) remote command execution exploit
A command line parsing vulnerability exists in KVIrc 3.4.2 Shiny which can be exploited by passing the '"' char followed by command line switches to 'irc:///', 'irc6:///', 'ircs:///' and 'ircs6:///' urls. The most interesting one is the -e switch followed by 'run' command, this runs calc.exe. The following links add a new user on target with admin privileges.
Mitigation:
Upgrade to the latest version of KVIrc 3.4.2 Shiny