Check Point Reference: | CPAI-2004-206 |
Date Published: | 19 Nov 2009 |
Severity: | Medium |
Last Updated: | Thursday 19 November, 2009 |
Source: | |
Industry Reference: | CVE-2004-1541 |
Protection Provided by: |
Security Gateway |
Who is Vulnerable? | |
Vulnerability Description | SecureCRT is a popular terminal application which provides support for a number of remote access protocols such as SSH1, SSH2 and Telnet. A vulnerability exists in the way VanDyke SecureCRT handles telnet URLs. Through the use of a telnet URL, SecureCRT can be remotely supplied a parameter which can be used to specify an arbitrary configuration folder; this configuration folder can reside on a remote shared resource. Because a configuration file can reference script code, an attacker can exploit this vulnerability to execute code on the vulnerable system in the context of the currently logged in user. In an attack case, the vulnerable application will start unexpectedly and attempt to establish a telnet session with a remote server. Any malicious script code referenced by the non-default configuration folder will be executed in the background without any warnings or user interaction. Further behavior of the attack target is entirely dependent on the nature of the executed code. The code is executed in the security context of the currently logged in user. |
This protection will detect and block attempts to entice the user to call the application associated with TELNET, while specifying a non-default configuration folder.This protection should be used when the application associated with TELNET on the clients' devices is VanDyke SecureCRT.
In order for the protection to be activated, update your Security Gateway product to the latest IPS update. For information on how to update IPS, go to SBP-2006-05, click on Protection tab and select the version of your choice.
This protection's log will contain the following information:
Attack Name: RDP Enforcement Violation.
Attack Information: VanDyke SecureCRT arbitrary configuration folder specification