Skip to content

Multiple security vulnerabilities in NVDA #515

@nvaccessAuto

Description

@nvaccessAuto

Reported by tspivey on 2009-12-26 05:33
Here we go again (2009.1 on win7).

  1. The log viewer allows the save-as command (On the log menu) to be run from secure desktops, allowing the by-now familiar running of cmd.exe.
  2. The various items in the help menu allow the running of external programs which contain open/save dialogs, again allowing this same exploit.

Proof of concept:

  1. Get to a secure desktop and open the log viewer. Go to log -> save As.
  2. dismiss any location error dialogs that appear. (enter or escape).
  3. Type %windir%\system32\c*.exe, press enter, pick cmd from the list, activate the context menu and run as administrator.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions