Security: SettingContent-ms extension bypasses 'dangerous file' prompt leading to WebExt RCE
Reported by
greencar...@hotmail.com,
Jun 11 2018
|
||||||||||
Issue descriptionVULNERABILITY DETAILS SettingContent-ms is a new windows 10 extension that can be used to execute arbitrary local files with parameters. VERSION Chrome Version: latest stable Operating System: windows 10 REPRODUCTION CASE Download attached SettingContent-ms file, or install attached extension for RCE. Please CC enigma0x3@gmail.com, he found the file and wrote about it an hour ago and I just so happen stumbled upon it and connected the dots.
,
Jun 11 2018
I'm sure you can get arbitrary code execution with just the stuff that's installed by default on Windows. So, definitely want this on the dangerous list. Thanks for the report! vakh, you want this one?
,
Jun 11 2018
,
Jun 11 2018
This looks like the original report: https://posts.specterops.io/the-tale-of-settingcontent-ms-files-f1ea253e4d39 Thanks for reporting it to us!
,
Jun 12 2018
The following revision refers to this bug: https://chromium.googlesource.com/chromium/src.git/+/2825a8e860b1d2f14d187be5fdf6b8e1f479e81d commit 2825a8e860b1d2f14d187be5fdf6b8e1f479e81d Author: Varun Khaneja <vakh@chromium.org> Date: Tue Jun 12 05:32:44 2018 Send pings when users download .settingcontent-ms files Bug: 851528 Cq-Include-Trybots: master.tryserver.chromium.linux:closure_compilation Change-Id: I950fe0b3241d1cff134957929f76eb3f1fb8b483 Reviewed-on: https://chromium-review.googlesource.com/1096342 Commit-Queue: Varun Khaneja <vakh@chromium.org> Reviewed-by: David Trainor <dtrainor@chromium.org> Reviewed-by: Jialiu Lin <jialiul@chromium.org> Cr-Commit-Position: refs/heads/master@{#566328} [modify] https://crrev.com/2825a8e860b1d2f14d187be5fdf6b8e1f479e81d/chrome/browser/resources/safe_browsing/download_file_types.asciipb [modify] https://crrev.com/2825a8e860b1d2f14d187be5fdf6b8e1f479e81d/components/download/internal/common/download_stats.cc [modify] https://crrev.com/2825a8e860b1d2f14d187be5fdf6b8e1f479e81d/tools/metrics/histograms/enums.xml
,
Jun 12 2018
Issue 851860 has been merged into this issue.
,
Jun 12 2018
Issue 851801 has been merged into this issue.
,
Jun 15 2018
,
Jun 16 2018
,
Jun 18 2018
,
Jun 20 2018
,
Jun 20 2018
,
Jun 27 2018
,
Sep 22
This bug has been closed for more than 14 weeks. Removing security view restrictions. For more details visit https://www.chromium.org/issue-tracking/autotriage - Your friendly Sheriffbot |
||||||||||
►
Sign in to add a comment |
||||||||||
Comment 1 by greencar...@hotmail.com
, Jun 11 2018