***** Security Alert - Notes URI handler vulnerability *****

Hello all

Forgive me if this has already been posted and forgive the annoying asterisks to make this post stand out but I thought I’d do my best to make everyone aware of this in case you’re affected.

Information is here…

http://www.idefense.com/application/poi/display?id=111&type=vulnerabilities

Simply put…

A URL can launch the Notes client using the = paramater to specify a path to a malicious data directory.

An attacker can set up a unc share on the net with a dodgy data direcory and cause you to launch Notes using that directory.

The vulnerability says that dll’s, etc can be launched but I’m not sure about this as the notes.ini points to the data directory, not the program directory.

Sounds like a biggie to me if you can see unc shares through your firewall. Any thoughts?

Subject: ***** Security Alert - Notes URI handler vulnerability *****

IMHO

Sounds like a big if. Anybody out there actually allow unc shares through the firewall?

If so my guess is you are probably looking at bigger vulnerabilities than this, targeted at a broader audience, say Windows OS users, as opposed to an attack targeted at Notes users.

Security in layers, you can’t realisticly expect to put an application in an unsafe environment and expect it to be completely safe. To some extent applications have to be able to rely on security enforcement at underlying levels (OS and network).

Subject: RE: ***** Security Alert - Notes URI handler vulnerability *****

Yes, we allow unc shares through the firewall.