CVE-2020-1300
published 2020-06-09CVE-2020-1300: A remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet files.To exploit the vulnerability, an attacker would have…
PriorityP265high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
59.52%
99.0th percentile
A remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet files.To exploit the vulnerability, an attacker would have to convince a user to either open a specially crafted cabinet file or spoof a network printer and trick a user into installing a malicious cabinet file disguised as a printer driver.The update addresses the vulnerability by correcting how Windows handles cabinet files., aka 'Windows Remote Code Execution Vulnerability'.
Affected
74 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect CAB files containing CFFILE szName fields with '../' (dot-dot-slash) directory traversal sequences, which bypass the '..' backslash check in NCabbingLibrary::FdiCabNotify() ↗
- →Monitor PrintBrmEngine.exe and the Print Spooler service (localspl.dll) for file write operations outside of %userprofiles%\AppData\Local\ temp directories, especially writes to sensitive system paths, as exploitation runs in SYSTEM context ↗
- →Monitor Print Management Console (printmanagement.msc) for CAB file extraction activity, as it shares the vulnerable NCabbingLibrary::FdiCabNotify() code path with the Print Spooler ↗
- ·No public exploits were reported at time of disclosure; exploitation was rated 'Less Likely' by Microsoft for both latest and older software releases ↗
- ·The directory traversal bypass specifically uses forward-slash '../' sequences; defenses or signatures that only check for backslash '..' traversal will miss this attack vector ↗
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cvm7-68v9-chqf: A remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet files
ghsa_unreviewed·2022-05-24
CVE-2020-1300 [MEDIUM] GHSA-cvm7-68v9-chqf: A remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet files
A remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet files.To exploit the vulnerability, an attacker would have to convince a user to either open a specially crafted cabinet file or spoof a network printer and trick a user into installing a malicious cabinet file disguised as a printer driver.The update addresses the vulnerability by correcting how Windows handles cabinet files., aka 'Windows Remote Code Execution Vulnerability'.
Microsoft
Windows Remote Code Execution Vulnerability
vendor_msrc·2020-06-09·CVSS 7.8
CVE-2020-1300 [HIGH] Windows Remote Code Execution Vulnerability
Windows Remote Code Execution Vulnerability
Description: A remote code execution vulnerability exists when Microsoft Windows fails to properly handle cabinet files.
To exploit the vulnerability, an attacker would have to convince a user to either open a specially crafted cabinet file or spoof a network printer and trick a user into installing a malicious cabinet file disguised as a printer driver.
The update addresses the vulnerability by correcting how Windows handles cabinet files.
Windows Print Spooler Components: Windows Print Spooler Components
Microsoft: Microsoft
Impact: Remote Code Execution
Exploit Status: Publicly Disclosed:No;Exploited:No;Latest Software Release:Exploitation Less Likely;Older Software Release:Exploitation Less Likely;DOS:N/A
Reference: https://catalog.upda
Suricata
ET EXPLOIT Potentially Malicious .cab Inbound (CVE-2020-1300)
suricata·2020-07-10·CVSS 8.8
CVE-2020-1300 [HIGH] ET EXPLOIT Potentially Malicious .cab Inbound (CVE-2020-1300)
ET EXPLOIT Potentially Malicious .cab Inbound (CVE-2020-1300)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Potentially Malicious .cab Inbound (CVE-2020-1300)"; flow:established,to_client; http.stat_code; content:"200"; http.response_body; content:"MSCF"; startswith; content:"../../"; distance:0; fast_pattern; pcre:"/^[a-z0-9\-_\.\/]+\x00/Ri"; reference:url,www.thezdi.com/blog/2020/7/8/cve-2020-1300-remote-code-execution-through-microsoft-windows-cab-files; classtype:attempted-admin; sid:2030493; rev:2; metadata:affected_product Windows_XP_Vista_7_8_10_Server_32_64_Bit, created_at 2020_07_10, cve CVE_2020_1300, deployment Perimeter, deployment Datacenter, performance_impact Low, confidence High, signature_severity Major, tag Description_Generated_By_Proofpoint_Nexus
Elastic
Deprecated - Suspicious PrintSpooler Service Executable File Creation
elastic_rules·CVSS 7.8
CVE-2020-1048 [HIGH] Deprecated - Suspicious PrintSpooler Service Executable File Creation
Deprecated - Suspicious PrintSpooler Service Executable File Creation
Detects attempts to exploit privilege escalation vulnerabilities related to the Print Spooler service. For more
information refer to the following CVE's - CVE-2020-1048, CVE-2020-1337 and CVE-2020-1300 and verify that the impacted
system is patched.
Query:
event.category : "file" and host.os.type : "windows" and event.type : "creation" and
process.name : "spoolsv.exe" and file.extension : "dll"
No public exploits indexed.
Securelist
IT threat evolution Q2 2020. PC statistics
blogs_securelist·2020-09-03
IT threat evolution Q2 2020. PC statistics
Table of Contents
- Quarterly figures
- Financial threats
- Ransomware programs
- Miners
- Vulnerable applications used by cybercriminals during cyberattacks
- Attacks on Apple macOS
- IoT attacks
- Attacks via web resources
- Local threats
Authors
- Victor Chebyshev
- Evgeny Lopatin
- Fedor Sinitsyn
- Denis Parinov
- Oleg Kupreev
- Alexey Kulaev
- Alexander Kolesnikov
IT threat evolution Q2 2020. Review
IT threat evolution Q2 2020. Mobile statistics
These statistics are based on detection verdicts of Kaspersky products received from users who consented to provide statistical data.
## Quarterly figures
According to Kaspersky Security Network, in Q2:
- Kaspersky solutions blocked 899,744,810 attacks launched from online resources in 191 countries across the globe.
- As many as 286,
Securelist
IT threat evolution Q2 2020. PC statistics
blogs_securelist·2020-09-03
IT threat evolution Q2 2020. PC statistics
Table of Contents
Quarterly figures
Financial threats
Financial threat statistics
Ransomware programs
Quarterly trend highlights
Number of new modifications
Number of users attacked by ransomware Trojans
Geography of attacks
Top 10 most common families of ransomware Trojans
Miners
Number of new modifications
Number of users attacked by miners
Geography of attacks
Vulnerable applications used by cybercriminals during cyberattacks
Attacks on Apple macOS
Threat geography
IoT attacks
IoT threat statistics
Threats loaded into traps
Attacks via web resources
Countries that are sources of web-based attacks: TOP 10
Countries where users faced the greatest risk of online infection
Local threats
Countries where users faced the highest risk of local infection
Authors
Victor
Trendmicro
Remote Code Execution Through Microsoft Windows CAB Files
blogs_trendmicro·2020-07-09·CVSS 8.8
CVE-2020-1300 [HIGH] Remote Code Execution Through Microsoft Windows CAB Files
## CVE-2020-1300: Remote Code Execution Through Microsoft Windows CAB Files
Learn remote code execution through Microsoft Windows CAB files.
By: Trend Micro Research Jul 09, 2020 Read time: ( words)
Save to Folio
In this excerpt of a Trend Micro Vulnerability Research Service vulnerability report, Pengsu Cheng and Yazhi Wang of the Trend Micro Research Team detail a recent code execution vulnerability in Microsoft Windows. The bug was originally discovered and reported by Zhipeng Huo (@R3dF09) of Tencent Security Xuanwu Lab. The following is a portion of their write-up covering CVE-2020-1300, with a few minimal modifications.
A directory traversal vulnerability has been reported in Microsoft Windows. The vulnerability is due to a lack of sanitization of file paths inside a CAB file. A
Trendmicro
Remote Code Execution Through Microsoft Windows CAB Files
blogs_trendmicro·2020-07-09·CVSS 8.8
CVE-2020-1300 [HIGH] Remote Code Execution Through Microsoft Windows CAB Files
# CVE-2020-1300: Remote Code Execution Through Microsoft Windows CAB Files
Learn remote code execution through Microsoft Windows CAB files.
By: Trend Micro Research
2020/07/09
Read time: ( words)
Save to Folio
In this excerpt of a Trend Micro Vulnerability Research Service vulnerability report, Pengsu Cheng and Yazhi Wang of the Trend Micro Research Team detail a recent code execution vulnerability in Microsoft Windows. The bug was originally discovered and reported by Zhipeng Huo (@R3dF09) of Tencent Security Xuanwu Lab. The following is a portion of their write-up covering CVE-2020-1300, with a few minimal modifications.
A directory traversal vulnerability has been reported in Microsoft Windows. The vulnerability is due to a lack of sanitization of file paths inside a CAB file. All
Trendmicro
Remote Code Execution Through Microsoft Windows CAB Files
blogs_trendmicro·2020-07-09·CVSS 8.8
CVE-2020-1300 [HIGH] Remote Code Execution Through Microsoft Windows CAB Files
## CVE-2020-1300: Remote Code Execution Through Microsoft Windows CAB Files
Learn remote code execution through Microsoft Windows CAB files.
By: Trend Micro Research 2020/07/09 Read time: ( words)
Save to Folio
In this excerpt of a Trend Micro Vulnerability Research Service vulnerability report, Pengsu Cheng and Yazhi Wang of the Trend Micro Research Team detail a recent code execution vulnerability in Microsoft Windows. The bug was originally discovered and reported by Zhipeng Huo (@R3dF09) of Tencent Security Xuanwu Lab. The following is a portion of their write-up covering CVE-2020-1300, with a few minimal modifications.
A directory traversal vulnerability has been reported in Microsoft Windows. The vulnerability is due to a lack of sanitization of file paths inside a CAB file. All
Qualys
June 2020 Patch Tuesday – 128 Vulns, 11 Critical, Sharepoint, Workstation, Adobe Patches | Qualys
blogs_qualys·2020-06-09·CVSS 8.8
CVE-2020-1299 [HIGH] June 2020 Patch Tuesday – 128 Vulns, 11 Critical, Sharepoint, Workstation, Adobe Patches | Qualys
This month’s Microsoft Patch Tuesday addresses 128 vulnerabilities with 11 of them labeled as Critical. The 11 Critical vulnerabilities cover SharePoint server, Browsers, Scripting Engines, Windows, GDI+, OLE and LNK files. Adobe issued patches today for Experience Manager, Flash Player and Framemaker.
### Workstation Patches
The Browser, Scripting Engine, LNK files (CVE-2020-1299), GDI+(CVE-2020-1248) and OLE (CVE-2020-1281) should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users.
### SharePoint
A remote code execution vulnerability (CVE-2020-1181) is patched in Sharepoint Server that would allow an authenticated user on a guest sys
Tenable
Microsoft’s June 2020 Patch Tuesday Addresses 129 CVEs Including Newly Disclosed SMBv3 Vulnerability (CVE-2020-1206)
blogs_tenable·2020-06-09·CVSS 7.5
[HIGH] Microsoft’s June 2020 Patch Tuesday Addresses 129 CVEs Including Newly Disclosed SMBv3 Vulnerability (CVE-2020-1206)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Qualys
June 2020 Patch Tuesday – 128 Vulns, 11 Critical, Sharepoint, Workstation, Adobe Patches
blogs_qualys·2020-06-09·CVSS 8.8
CVE-2020-1299 [HIGH] June 2020 Patch Tuesday – 128 Vulns, 11 Critical, Sharepoint, Workstation, Adobe Patches
This month’s Microsoft Patch Tuesday addresses 128 vulnerabilities with 11 of them labeled as Critical. The 11 Critical vulnerabilities cover SharePoint server, Browsers, Scripting Engines, Windows, GDI+, OLE and LNK files. Adobe issued patches today for Experience Manager, Flash Player and Framemaker.
## Workstation Patches
The Browser, Scripting Engine, LNK files ( CVE-2020-1299 ), GDI+( CVE-2020-1248 ) and OLE ( CVE-2020-1281 ) should be prioritized for workstation-type devices, meaning any system that is used for email or to access the internet via a browser. This includes multi-user servers that are used as remote desktops for users.
## SharePoint
A remote code execution vulnerability ( CVE-2020-1181 ) is patched in Sharepoint Server that would allow an authenticated user on a gue
Huntress
What Is DLL Hijacking? How to Detect & Prevent It | Huntress
blogs_huntress
What Is DLL Hijacking? How to Detect & Prevent It | Huntress
## What is DLL hijacking?
DLL hijacking is when a Windows application loads a malicious DLL (Dynamic Link Library) instead of a legitimate one, because the attacker has placed their DLL where the system expects to find the original. This trick works because many applications don’t specify the full, trusted path to their needed DLLs. Instead, they rely on Windows’ default search order, which isn’t always secure. The result? The attacker’s code runs with the same privileges as the application, opening doors for bad actors.
## Purpose behind DLL hijacking
Gain unauthorized access or control
Escalate user privileges
Maintain stealthy persistence
Deploy malware while evading detection
## How DLL hijacking works step by step
Want to know how attackers pull off DLL hijacking? Here’s how i
2020-06-09
Published