Lucene search

K
zdiMoritz JodeitZDI-12-154
HistoryAug 22, 2012 - 12:00 a.m.

IBM Lotus Notes URL Command Injection Remote Code Execution Vulnerability

2012-08-2200:00:00
Moritz Jodeit
www.zerodayinitiative.com
68

EPSS

0.965

Percentile

99.6%

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of IBM Lotus Notes. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within notes.exe. When handling URLs, it is possible to inject the -RPARAMS command line argument into the call to notes.exe, which will then launch rcplauncher.exe. Including the java -vm command will allow for the attacker to execute code under the context of the process.