Reported by tspivey on 2009-12-26 05:33
Here we go again (2009.1 on win7).
- The log viewer allows the save-as command (On the log menu) to be run from secure desktops, allowing the by-now familiar running of cmd.exe.
- The various items in the help menu allow the running of external programs which contain open/save dialogs, again allowing this same exploit.
Proof of concept:
- Get to a secure desktop and open the log viewer. Go to log -> save As.
- dismiss any location error dialogs that appear. (enter or escape).
- Type %windir%\system32\c*.exe, press enter, pick cmd from the list, activate the context menu and run as administrator.
Reported by tspivey on 2009-12-26 05:33
Here we go again (2009.1 on win7).
Proof of concept: