Quantcast
Channel: BOT24
Viewing all articles
Browse latest Browse all 8064

MS14-019 – Fixing a binary hijacking via .cmd or .bat file

$
0
0
Command (.cmd) and batch (.bat) files can be directly provided as input to the CreateProcess as if it is an executable. CreateProcess uses the cmd.exe automatically to run the input .cmd or .bat.


Today, with the bulletin MS14-019 we are fixing a vulnerability, where in particular scenario it is possible to hijack the cmd.exe with a copy present in the attacker controlled current working directory (CWD) of an affected application.

read more.......http://blogs.technet.com/b/srd/archive/2014/04/08/ms14-019-fixing-a-binary-hijacking-via-cmd-or-bat-file.aspx

Viewing all articles
Browse latest Browse all 8064

Trending Articles