vendor:
Windows
by:
John Page (aka hyp3rlinx)
9.3
CVSS
HIGH
Insufficient UI Warning Remote Code Execution
20
CWE
Product Name: Windows
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: No
Related CWE: ZDI-19-013, ZDI-CAN-6920
CPE: o:microsoft:windows
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows
2019
Microsoft Windows VCF File Insufficient Warning Remote Code Execution
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of VCard files. Crafted data in a VCard file can cause Windows to display a dangerous hyperlink. The user interface fails to provide any indication of the hazard. An attacker can leverage this vulnerability to execute code in the context of the current user.
Mitigation:
Users should be aware of the potential risks of opening VCF files from untrusted sources. It is recommended to use a secure email service to send and receive VCF files.