Microsoft Windows NT and 2000 cmd.exe CD path name buffer overflow

win-cmd-cd-bo (11329) The risk level is classified as HighHigh Risk

Description:

Microsoft Windows NT and Windows 2000 systems are vulnerable to a buffer overflow in the cmd.exe command prompt, caused by improper bounds checking of file paths. By issuing a CD command with a file path of more than 256 characters, a local attacker could overflow and cause the cmd.exe window to crash, and possibly execute arbitrary code on the system on Windows NT 4.0 systems or cause the CD command to fail on Windows 2000 systems.

Platforms Affected:

  • Microsoft, Windows 2000
  • Microsoft, Windows NT 4.0

Remedy:

No remedy available as of November 15, 2008.

Consequences:

Gain Privileges

References:

  • BugTraq Mailing List, Tue Feb 11 2003 - 04:15:13 CST , SECURITY.NNOV: Windows NT 4.0/2000 cmd.exe long path buffer overflow/DoS at http://archives.neohapsis.com/archives/bugtraq/2003-02/0138.html.
  • BID-6829: Microsoft Windows NT/2000 cmd.exe CD Buffer Overflow Vulnerability
  • CVE-2003-1407: Buffer overflow in cmd.exe in Windows NT 4.0 may allow local users to execute arbitrary code via a long pathname argument to the cd command.

Reported:

Feb 11, 2003

The information within this database may change without notice. Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the author/distributor (Internet Security Systems X-Force) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

Copyright (c) 1994-2008 Internet Security Systems, Inc. All rights reserved worldwide.

For corrections or additions please email xforce@iss.net

Return to the main page