Time: 2012-09-26
[Vulnerability description]
When using the CreateProcess function, when the first parameter lpApplicationName is NULL and the second parameter lpCommandLine contains spaces without double quotation marks, the function will be truncated during execution, for example, c: \ program files \ sub dir \ program name, the program will search for programs in the following column order:
C: \ program.exe files \ sub dir \ program name
C: \ programfiles \ sub.exe dir \ program name
C: \ programfiles \ sub dir \ program.exe name
C: \ programfiles \ sub dir \ program name.exe
DEMO code:
# Include <stdio. h>
# Include <windows. h>
Int main ()
{
Char cmd [] = "C: \ Program Files \ test.exe"; // test.exeis the command console cmd.exe, and C: \ program.exeis the calculator calc.exe
STARTUPINFO si = {sizeof (si )};
PROCESS_INFORMATION pi;
Si. dwFlags = STARTF_USESHOWWINDOW;
Si. wShowWindow = TRUE;
CreateProcess (NULL, cmd, NULL, NULL, FALSE, 0, NULL, NULL, & si, & pi );
Return 0;
}
After execution, the calculator calc.exewill be opened, instead of cmd.exe:
Click to view original size
[Vulnerability repair]
There are two major repair methods:
1. Place the execution command string in the 1st parameter lpApplicationName:
CreateProcess (cmd, NULL, FALSE, 0, NULL, NULL, & si, & pi );
2. When the command string is placed in 2nd parameters, double quotation marks are applied to include:
Char cmd [] = "\" C: \ Program Files \ test.exe \"";