ID

VAR-201401-0042


CVE

CVE-2013-1361


TITLE

Lenovo Thinkpad Bluetooth with Enhanced Data Rate Vulnerability to execute arbitrary code in software

Trust: 0.8

sources: JVNDB: JVNDB-2013-005881

DESCRIPTION

Untrusted search path vulnerability in Lenovo Thinkpad Bluetooth with Enhanced Data Rate Software 6.4.0.2900 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse DLL that is located in the same folder as a file that is processed by Lenovo Bluetooth. Supplementary information : CWE Vulnerability type by CWE-426: Untrusted Search Path ( Unreliable search path ) Has been identified. Attackers can exploit this vulnerability to execute arbitrary code in the context of the user running the vulnerable application. Bluetooth with Enhanced Data Rate Software 6.4.0.2900 is vulnerable; other versions may also be affected. ---------------------------------------------------------------------- The final version of the CSI 6.0 has been released. Find out why this is not just another Patch Management solution: http://secunia.com/blog/325/ ---------------------------------------------------------------------- TITLE: Lenovo Bluetooth with Enhanced Data Rate Software Insecure Library Loading Vulnerability SECUNIA ADVISORY ID: SA51846 VERIFY ADVISORY: Secunia.com http://secunia.com/advisories/51846/ Customer Area (Credentials Required) https://ca.secunia.com/?page=viewadvisory&vuln_id=51846 RELEASE DATE: 2013-01-22 DISCUSS ADVISORY: http://secunia.com/advisories/51846/#comments AVAILABLE ON SITE AND IN CUSTOMER AREA: * Last Update * Popularity * Comments * Criticality Level * Impact * Where * Solution Status * Operating System / Software * CVE Reference(s) http://secunia.com/advisories/51846/ ONLY AVAILABLE IN CUSTOMER AREA: * Authentication Level * Report Reliability * Secunia PoC * Secunia Analysis * Systems Affected * Approve Distribution * Remediation Status * Secunia CVSS Score * CVSS https://ca.secunia.com/?page=viewadvisory&vuln_id=51846 ONLY AVAILABLE WITH SECUNIA CSI AND SECUNIA PSI: * AUTOMATED SCANNING http://secunia.com/vulnerability_scanning/personal/ http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/ DESCRIPTION: Microsoft has reported a vulnerability in Lenovo Bluetooth with Enhanced Data Rate Software, which can be exploited by malicious people to compromise a user's system. The vulnerability is caused due to the application loading libraries in an insecure manner. This can be exploited to load arbitrary libraries by tricking a user into opening certain files on a remote WebDAV or SMB share. Successful exploitation allows execution of arbitrary code. The vulnerability is reported in versions 6.4.0.2900 and prior. SOLUTION: Update to version 6.5.1.2700. Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ PROVIDED AND/OR DISCOVERED BY: Haifei Li, Microsoft. ORIGINAL ADVISORY: Lenovo: http://download.lenovo.com/ibmdl/pub/pc/pccbbs/mobiles/g4wb10ww.txt MSVR: http://technet.microsoft.com/en-us/security/msvr/msvr13-001 OTHER REFERENCES: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ DEEP LINKS: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED DESCRIPTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXTENDED SOLUTION: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ EXPLOIT: Further details available in Customer Area: http://secunia.com/vulnerability_intelligence/ ---------------------------------------------------------------------- About: This Advisory was delivered by Secunia as a free service to help private users keeping their systems up to date against the latest vulnerabilities. Subscribe: http://secunia.com/advisories/secunia_security_advisories/ Definitions: (Criticality, Where etc.) http://secunia.com/advisories/about_secunia_advisories/ Please Note: Secunia recommends that you verify all advisories you receive by clicking the link. Secunia NEVER sends attached files with advisories. Secunia does not advise people to install third party patches, only use those supplied by the vendor. ---------------------------------------------------------------------- Unsubscribe: Secunia Security Advisories http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org ----------------------------------------------------------------------

Trust: 2.07

sources: NVD: CVE-2013-1361 // JVNDB: JVNDB-2013-005881 // BID: 57504 // VULHUB: VHN-61363 // PACKETSTORM: 119705

AFFECTED PRODUCTS

vendor:lenovomodel:thinkpad bluetooth with enhanced data rate softwarescope:lteversion:6.4.0.2900

Trust: 1.8

vendor:lenovomodel:thinkpad bluetooth with enhanced data rate softwarescope:eqversion:6.4.0.2900

Trust: 0.6

vendor:lenovomodel:bluetooth with enhanced data rate softwarescope:eqversion:6.4.0.2900

Trust: 0.3

vendor:lenovomodel:bluetooth with enhanced data rate softwarescope:neversion:6.5.1.2700

Trust: 0.3

sources: BID: 57504 // JVNDB: JVNDB-2013-005881 // CNNVD: CNNVD-201301-442 // NVD: CVE-2013-1361

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2013-1361
value: HIGH

Trust: 1.0

NVD: CVE-2013-1361
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201301-442
value: CRITICAL

Trust: 0.6

VULHUB: VHN-61363
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2013-1361
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-61363
severity: HIGH
baseScore: 9.3
vectorString: AV:N/AC:M/AU:N/C:C/I:C/A:C
accessVector: NETWORK
accessComplexity: MEDIUM
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 8.6
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

sources: VULHUB: VHN-61363 // JVNDB: JVNDB-2013-005881 // CNNVD: CNNVD-201301-442 // NVD: CVE-2013-1361

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

problemtype:CWE-Other

Trust: 0.8

sources: JVNDB: JVNDB-2013-005881 // NVD: CVE-2013-1361

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-201301-442

TYPE

Design Error

Trust: 0.3

sources: BID: 57504

CONFIGURATIONS

sources: JVNDB: JVNDB-2013-005881

PATCH

title:ThinkPad Bluetooth 3.0, 4.0 ソフトウェア (Windows 7 32bit, 64bit) - ThinkPadurl:http://support.lenovo.com/ja_JP/downloads/detail.page?DocID=DS029104

Trust: 0.8

title:Microsoft Vulnerability Research Advisory MSVR13-001url:http://technet.microsoft.com/en-us/security/msvr/msvr13-001

Trust: 0.8

title:マイクロソフト脆弱性調査アドバイザリ MSVR13-001url:http://technet.microsoft.com/ja-jp/security/msvr/msvr13-001

Trust: 0.8

title:g4wb10wwurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=47679

Trust: 0.6

sources: JVNDB: JVNDB-2013-005881 // CNNVD: CNNVD-201301-442

EXTERNAL IDS

db:NVDid:CVE-2013-1361

Trust: 2.8

db:BIDid:57504

Trust: 2.0

db:SECUNIAid:51846

Trust: 1.8

db:OSVDBid:89483

Trust: 1.7

db:JVNDBid:JVNDB-2013-005881

Trust: 0.8

db:CNNVDid:CNNVD-201301-442

Trust: 0.7

db:XFid:81428

Trust: 0.6

db:VULHUBid:VHN-61363

Trust: 0.1

db:PACKETSTORMid:119705

Trust: 0.1

sources: VULHUB: VHN-61363 // BID: 57504 // JVNDB: JVNDB-2013-005881 // PACKETSTORM: 119705 // CNNVD: CNNVD-201301-442 // NVD: CVE-2013-1361

REFERENCES

url:http://technet.microsoft.com/en-us/security/msvr/msvr13-001

Trust: 1.8

url:http://www.securityfocus.com/bid/57504

Trust: 1.7

url:http://www.osvdb.org/89483

Trust: 1.7

url:http://secunia.com/advisories/51846

Trust: 1.7

url:https://exchange.xforce.ibmcloud.com/vulnerabilities/81428

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2013-1361

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2013-1361

Trust: 0.8

url:http://xforce.iss.net/xforce/xfdb/81428

Trust: 0.6

url:http://blog.rapid7.com/?p=5325

Trust: 0.3

url:http://blogs.technet.com/b/srd/archive/2010/08/23/more-information-about-dll-preloading-remote-attack-vector.aspx

Trust: 0.3

url:http://www.attackvector.org/new-dll-hijacking-exploits-many/

Trust: 0.3

url:http://www.microsoft.com/technet/security/advisory/2269637.mspx

Trust: 0.3

url:http://download.lenovo.com/ibmdl/pub/pc/pccbbs/mobiles/g4wb10ww.txt

Trust: 0.1

url:http://secunia.com/vulnerability_intelligence/

Trust: 0.1

url:http://secunia.com/advisories/secunia_security_advisories/

Trust: 0.1

url:http://secunia.com/vulnerability_scanning/corporate/wsus_sccm_3rd_third_party_patching/

Trust: 0.1

url:http://secunia.com/advisories/51846/

Trust: 0.1

url:http://secunia.com/advisories/51846/#comments

Trust: 0.1

url:https://ca.secunia.com/?page=viewadvisory&vuln_id=51846

Trust: 0.1

url:http://secunia.com/vulnerability_scanning/personal/

Trust: 0.1

url:http://secunia.com/sec_adv_unsubscribe/?email=packet%40packetstormsecurity.org

Trust: 0.1

url:http://secunia.com/blog/325/

Trust: 0.1

url:http://secunia.com/advisories/about_secunia_advisories/

Trust: 0.1

sources: VULHUB: VHN-61363 // BID: 57504 // JVNDB: JVNDB-2013-005881 // PACKETSTORM: 119705 // CNNVD: CNNVD-201301-442 // NVD: CVE-2013-1361

CREDITS

Haifei Li of Microsoft

Trust: 0.3

sources: BID: 57504

SOURCES

db:VULHUBid:VHN-61363
db:BIDid:57504
db:JVNDBid:JVNDB-2013-005881
db:PACKETSTORMid:119705
db:CNNVDid:CNNVD-201301-442
db:NVDid:CVE-2013-1361

LAST UPDATE DATE

2025-04-11T22:55:49.624000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-61363date:2017-08-29T00:00:00
db:BIDid:57504date:2013-01-22T00:00:00
db:JVNDBid:JVNDB-2013-005881date:2014-01-23T00:00:00
db:CNNVDid:CNNVD-201301-442date:2014-03-11T00:00:00
db:NVDid:CVE-2013-1361date:2025-04-11T00:51:21.963

SOURCES RELEASE DATE

db:VULHUBid:VHN-61363date:2014-01-21T00:00:00
db:BIDid:57504date:2013-01-22T00:00:00
db:JVNDBid:JVNDB-2013-005881date:2014-01-23T00:00:00
db:PACKETSTORMid:119705date:2013-01-22T04:45:55
db:CNNVDid:CNNVD-201301-442date:2013-01-24T00:00:00
db:NVDid:CVE-2013-1361date:2014-01-21T18:55:09.303