RIM have released a KB warning of a vulnerability on all Desktop Manager softwares prior to 5.0.1. The vulnerability scores quite high in the Common Vulnerability Scoring System (CVSS) at 9.3. OYXin of Nevis Labs, Aviram Networks, Inc., found and reported this issue to RIM.
Details are below:
Overview
This advisory relates to a vulnerability in a Lotus Notes Intellisync DLL that the BlackBerry Desktop Manager may use. This vulnerability may allow a malicious user to perform an attack that leverages social engineering to achieve remote code execution on the computer running the BlackBerry Desktop Manager. If the legitimate (logged in) user clicks a link to a malicious web site (for example, in an email message, in a browser, or an instant message) on the computer that is running the BlackBerry Desktop Manager, a vulnerability in an Intellisync component could allow the malicious user who sent the link or created the malicious web site to execute code on the computer using the privileges of the legitimate user. Continue reading »
