Skip to main content

Microsoft Windows Search Code Execution Vulnerabilities (10 December 2008)

Last Update Date: 28 Jan 2011 Release Date: 10 Dec 2008 4423 Views

RISK: Medium Risk

1. Windows Saved Search Vulnerability

A remote code execution vulnerability exists when saving a specially crafted search file within Windows Explorer. This operation causes Windows Explorer to exit and restart in an exploitable manner.

2. Windows Search Parsing Vulnerability

A remote code execution vulnerability exists in Windows Explorer that allows an attacker to construct a malicious web page that includes a call to the search-ms protocol handler. The protocol handler in turn passes untrusted data to Windows Explorer.