Vulnerability in the BlackBerry Desktop Manager allows remote code executionContents [show] Products
EnvironmentResearch In Motion (RIM) has tested the following software to determine which versions or editions are affected. Other versions or editions are either past their support life cycle or are not affected. Affected Software
|
Software
|
Component/Functionality
| Severity Rating (CVSS score)
|
|
| Non-Affected Software
Change Log
OverviewThis advisory relates to a vulnerability in a Lotus Notes Intellisync DLL that the BlackBerry Desktop Manager may use. This vulnerability may allow a malicious user to perform an attack that leverages social engineering to achieve remote code execution on the computer running the BlackBerry Desktop Manager. If the legitimate (logged in) user clicks a link to a malicious web site (for example, in an email message, in a browser, or an instant message) on the computer that is running the BlackBerry Desktop Manager, a vulnerability in an Intellisync component could allow the malicious user who sent the link or created the malicious web site to execute code on the computer using the privileges of the legitimate user. Note: The affected Lotus Notes Intellisync DLL is included by default in all BlackBerry Desktop Manager installations. This vulnerability exists whether or not the DLL is used after installation. Issue Severity: This vulnerability has a Common Vulnerability Scoring System (CVSS) score of 9.3. Issue Status: Vulnerability confirmed. For more information, see the Resolution section.References:
Recommendation: Complete the resolution actions documented in this advisory. Mitigations:
RIM thanks OYXin of Nevis Labs, Aviram Networks, Inc., for reporting this issue to RIM, and working with RIM to protect its customers. ImpactProblemIf the malicious user performs an attack designed to decieve the legitimate user into clicking a link to a web site that appears to be from a trusted source, and the legitimate user chooses to access that site from the computer that is running the BlackBerry Desktop Manager, the user might be deceived into browsing to a web page that the malicious user has designed to perform remote code execution using the legitimate user's privileges on the computer. The BlackBerry Desktop Manager does not need to be running for a malicious user to exploit this vulnerability. ResolutionRIM has issued a software update that resolves this issue in BlackBerry Desktop Software version 5.0.1 and later. Upgrade the BlackBerry Desktop Software
Note: The minimum BlackBerry Desktop Software version you can install to resolve this issue is 5.0.1.
WorkaroundYou can disable the Lotus Notes Intellisync functionality by unregistering the Intellisync component DLL, lnresobject.dll. Disabling the functionality prevents a malicious user from exploiting the vulnerability but also removes the ability to synchronize data between Lotus Notes and the BlackBerry Desktop Manager. To unregister the DLL on the computer running the BlackBerry Desktop Manager, complete the following step for your BlackBerry Desktop Software version. BlackBerry Desktop Software versions earlier than 4.3.0On the computer running the BlackBerry Desktop Manager, at a command line enter the following command:
BlackBerry Desktop Software version 4.3.0 and laterOn the computer running the BlackBerry Desktop Manager, at a command line enter the following command:
Additional InformationCVSS is a vendor agnostic, industry open standard designed to convey the severity of vulnerabilities. CVSS scores may be used to determine the urgency for update deployment within an organization. CVSS scores range from 0.0 (no vulnerability) to 10.0 (critical). RIM uses CVSS in vulnerability assessments to present an immutable characterization of security issues. RIM assigns all security relevant issues a non-zero score. Visit www.blackberry.com/security for more information on BlackBerry security.
Disclaimer© 2009 Research In Motion Limited. All rights reserved. BlackBerry®, RIM®, Research In Motion®, SureType®, SurePress™ and related trademarks, names and logos are the property of Research In Motion Limited and are registered and/or used in the U.S. and countries around the world. All other trademarks are the property of their respective owners. TO THE MAXIMUM EXTENT PERMITTED BY APPLICABLE LAW IN YOUR JURISDICTION, RIM SHALL HAVE NO OTHER OBLIGATION, DUTY, OR LIABILITY WHATSOEVER IN CONTRACT, TORT, OR OTHERWISE TO YOU INCLUDING ANY LIABILITY FOR NEGLIGENCE OR STRICT LIABILITY. THE LIMITATIONS, EXCLUSIONS, AND DISCLAIMERS HEREIN SHALL APPLY: (A) IRRESPECTIVE OF THE NATURE OF THE CAUSE OF ACTION, DEMAND, OR ACTION BY YOU INCLUDING BUT NOT LIMITED TO BREACH OF CONTRACT, NEGLIGENCE, TORT, STRICT LIABILITY OR ANY OTHER LEGAL THEORY AND SHALL SURVIVE A FUNDAMENTAL BREACH OR BREACHES OR THE FAILURE OF THE ESSENTIAL PURPOSE OF THIS AGREEMENT OR OF ANY REMEDY CONTAINED HEREIN; AND (B) TO RIM AND ITS AFFILIATED COMPANIES, THEIR SUCCESSORS, ASSIGNS, AGENTS, SUPPLIERS (INCLUDING AIRTIME SERVICE PROVIDERS), AUTHORIZED RIM DISTRIBUTORS (ALSO INCLUDING AIRTIME SERVICE PROVIDERS) AND THEIR RESPECTIVE DIRECTORS, EMPLOYEES AND INDEPENDENT CONTRACTORS. IN ADDITION TO THE LIMITATIONS AND EXCLUSIONS SET OUT ABOVE, IN NO EVENT SHALL ANY DIRECTOR, EMPLOYEE, AGENT, DISTRIBUTOR, SUPPLIER, INDEPENDENT CONTRACTOR OF RIM OR ANY AFFILIATES OF RIM HAVE ANY LIABILITY ARISING FROM OR RELATED TO THE DOCUMENTATION. The terms of use of any RIM product or service are set out in a separate license or other agreement with RIM applicable thereto. NOTHING IN THIS DOCUMENTATION IS INTENDED TO SUPERSEDE ANY EXPRESS WRITTEN AGREEMENTS OR WARRANTIES PROVIDED BY RIM FOR PORTIONS OF ANY RIM PRODUCT OR SERVICE OTHER THAN THIS DOCUMENTATION. DisclaimerBy downloading, accessing or otherwise using the Knowledge Base documents you agree: (a) that the terms of use for the documents found at http://www.blackberry.com/support/knowledgebase/disclaimer.shtml apply to your use or reference to these documents; and (b) not to copy, distribute, disclose or reproduce, in full or in part any of the documents without the express written consent of RIM. Visit the BlackBerry Technical Solution Center at http://www.blackberry.com/btsc. |