| VID |
28097 |
| Severity |
40 |
| Port |
139,445 |
| Protocol |
TCP |
| Class |
SMB |
| Detailed Description |
The SecureCRT software, according to its version number, has a remote command execution vulnerability. VanDyke Software's SecureCRT is a terminal emulator for Internet and intranet use with support for Secure Shell (SSH1 and SSH2) as well as Telnet and rlogin protocols. SecureCRT client versions 4.x.x prior to 4.1.9 could allow a remote attacker to execute arbitrary commands. SecureCRT implements a protocol handler that is installed by default and facilitates the use of interactive telnet terminals in active browser windows. Furthermore this terminal execution can be automated by remote users through an HTML iframe tag. The problem presents itself when a malicious HTML script is loaded that activates the affected protocol handler. Apparently the affected application takes a command line argument, '/F', that allows a user to specify the directory of the configuration file. This configuration file facilitates script execution by allowing a user to specify a configuration script to be run upon execution. By creating a specially-crafted Web page that uses the /F command line option and contains a Telnet:// URL that specifies an arbitrary configuration folder from an SMB share, a remote attacker could execute arbitrary commands on the system, once the Web page is visited.
* Note: This check requires an account with Guest or upper privileges which can access the registry of the remote host to scan. Absence of these condition will result in the check not being performed and a False Negative for all vulnerable hosts.
* References: http://www.securiteam.com/windowsntfocus/6Z00N1FBPK.html http://secunia.com/advisories/13275/ http://www.security-assessment.com/Papers/SecureCRT_Remote_Command_Execution.pdf
* Platforms Affected: SecureCRT 4.x.x prior to 4.1.9 Microsoft Windows Any version |
| Recommendation |
Upgrade to the latest version of SecureCRT (4.1.9 or later), available from the VanDyke Software Download SecureCRT Web page at http://www.vandyke.com/download/securecrt/index.html |
| Related URL |
(CVE) |
| Related URL |
11731 (SecurityFocus) |
| Related URL |
18201 (ISS) |
|