Ticket #515 (closed defect: fixed)
Multiple security vulnerabilities in NVDA
| Reported by: | tspivey | Owned by: | |
|---|---|---|---|
| Priority: | critical | Milestone: | 2010.1 |
| Component: | Core | Version: | 2009.1rc1 |
| Keywords: | security | Cc: | |
| Operating system: | Windows 7 | Blocked by: | |
| Blocking: |
Description
Here we go again (2009.1 on win7).
1. The log viewer allows the save-as command (On the log menu) to be run from secure desktops, allowing the by-now familiar running of cmd.exe.
2. The various items in the help menu allow the running of external programs which contain open/save dialogs, again allowing this same exploit.
Proof of concept:
1. Get to a secure desktop and open the log viewer. Go to log -> save As.
2. dismiss any location error dialogs that appear. (enter or escape).
3. Type %windir%\system32\c*.exe, press enter, pick cmd from the list, activate the context menu and run as administrator.


NVDA is developed by