Terminal Server Desktop, Explorer.exe, Launches from a Published Application

Citrix states in their article: CTX991230

Document ID: CTX991230, Created on: Aug 5, 2002, Updated: May 17, 2006

Products: Citrix MetaFrame XP 1.0 for Microsoft Windows 2000, Citrix MetaFrame XP 1.0 for Microsoft NT 4.0 Server Terminal Server Edition, Citrix MetaFrame XP 1.0 for Microsoft Windows 2003, Citrix MetaFrame Presentation Server 3.0 for Microsoft Windows 2000, Citrix MetaFrame Presentation Server 3.0 for Microsoft Windows 2003, Citrix Presentation Server 4.0 for Microsoft Windows 2000, Citrix Presentation Server 4.0 for Microsoft Windows 2003

Problem Description

When connecting to an ICA published application either in a fixed or seamless window mode, or an RDP session configured for an Initial Program, it may be possible to launch the Explorer desktop.

Invoking the desktop from a published application session is perceived as a security issue.

CTX101664 – User Can Launch Desktop Instead Of Published Application

CTX108784 – Preventing the Explorer.exe from Launching in Shell Mode

CTX103376 – How to disable the Windows explorer functions in a published Internet Explorer

CTX112134 – ICA Seamless Host Agent Dialog box Displayed when Connecting to a Seamless Application

Examples

1. Winword.exe. If a Word document contains a hyperlink to a UNC folder such as \\Server\Share and the hyperlink is clicked, an instance of Explorer.exe is started and the desktop is displayed.

2. Accessing the Microsoft Outlook Web Toolbar. This allows a user to simply type file://x:/winnt/explorer.exe in the Text control.

Below is a documented workaround for examples 1 and 2 that can be used until Microsoft implements new code to address this issue.

WARNING! Using Registry Editor incorrectly can cause serious problems that may require you to reinstall your operating system. Citrix cannot guarantee that problems resulting from the incorrect use of Registry Editor can be solved. Use Registry Editor at your own risk.

To launch Internet Explorer instead of Explorer to view files in the UNC folder, modify the keys below. (Please note that @ means the Default string value). Open the registry on the server hosting MetaFrame and change the following keys.

HKCR\Folder\shell\explore\command

"@ = "c:\progra~1\intern~1\iexplore.exe" -nohome %L" (or the path where you have Internet Explorer installed on your machines).

HKCR\Folder\shell\explore\ddexec

"@ = """

HKCR\Folder\shell\explore\ddexec\application

"@ = "IExplore""

3. Pressing Ctrl+F1 inside an ICA session brings up the Windows Security dialog box. Set a policy to disable Task Manager from being executed or users can do a "file" - "new task" and type explorer.exe.

4. Restrict user access to a command prompt. This prevents users from launching a process from a command line.

5. Configure the Citrix ICA listener to "run only published applications" and publish the desktop for only the users or groups allowed to access the server desktop.

6. Lock down Explorer with policies to prevent access to the desktop.

By default, in some applications, the user has access to Explorer when opening or saving a file. For example, in Notepad, if you go into File/Save As, it brings up the file selector. If you choose a file and right-click with the mouse, you can access explorer. In a published application, this may bring up a Citrix error message about CTXUNDO not being able to find a file. After the error, you end up with the desktop of the MetaFrame server.

In another scenario, the user may receive the desktop from published Internet Explorer.

Through an ICA session on a client device:

• Run Internet Explorer as a published application.

• Select File and click Open.

• When opened, type explorer in the blank field. The server desktop opens.

You cannot apply the Disable Windows Explorer's default context menu policy after you install Internet Explorer 6 SP1

Resolution

Windows 2000

Create the following registry entries to prevent Explorer from being executed:

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoRun (DWORD) = 1
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\NoFileUrl (DWORD) = 1

You can also use Group Policies to lock down the server.

You cannot apply the Disable Windows Explorer's default context menu policy after you install Internet Explorer 6 SP1

Terminal Server 4.0

Explorer Context Menu:
Category: Windows NT Shell
Subcategory: Restrictions
Selection: Disable Explorers default context menu
Description: Removes the context menu that would normally appear when the user right clicks on the desktop or in the Explorer right results pane. (This option was added in Service Pack 2.)
Key: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion \Policies\Explorer
Registry Value Registry Data Description
NoViewContextMenu REG_DWORD Off = 0 or value is removed; On = 1
See Q185590 for additional information.

7. For additional information in locking down a Terminal Services environment, see: CTX9333 - Tricerate Desktop Management , Locking Down Windows Server 2003 Terminal Server Sessions, and Securing Windows 2000 Terminal Services.

8. Back Door to RUN Command in Microsoft Office97 Applications.

In all Office97 applications, there is a back door to the RUN command.

a.. Launch one of the Office applications; for example, Word97.

b. Click Help, About Microsoft Word, and then System Info.

c. From the File pull-down menu, select Run. The Run Application dialog box appears. Select an
application to run as well as provide a command line to execute applications.

NOTE: This applies to all the applications in the Office Suite.

To prevent this from occurring, you must deny users the ability to execute Msinfo32.exe.
Use NTFS permissions to restrict access to this file.

9. You may experience problems in Windows Explorer or in the Windows shell after you install security update MS06-015



Primary links

Custom Search

Who's new

  • maczugaher
  • locksgydff
  • isotheces
  • ahundredyears7
  • Jacomijntjefu

Who's online

There are currently 0 users and 5 guests online.

KrissysCorner.com RuthSwensonLaw.com CreativeLizardProductions.com

DISCLAIMER:

None of this has anything to do with us, someone else is responsible for the entire thing, and we have no idea who or why. We do not know anything about it. It may be alien life forms for all we know: we haven't a clue. You cannot blame us for anything that may result from your visit. That was entirely your own personal choice, made by you of your own volition, and without our knowledge. We do not, after all, have any control over you and cannot by any stretch of the imagination be expected to accept or acknowledge, be it legally or morally, any accountability for decisions made by you on an independent basis, utilizing your own free will, and without our intervention. We are therefore in no way, shape, or form answerable to anyone for any consequences arising from the aforementioned or indeed any other actions, similar or otherwise, because it was not us that did, or did not do anything. It is not even remotely our fault, and we are in no way prepared or willing to accept any liability, not even slightly, ever. We are, in fact completely and utterly blameless, in that it is definitely not our concern, and no blame can possibly be laid at our doorstep, even if we had one, the possession of which we hereby reserve as being entirely our own free choice. The onus is not on us at all, and furthermore, never has been. The entire matter is wholly beyond our control, and completely out of our hands, each of which are washed scrupulously clean of the whole business. We are not accountable for anything at all, and we hereby categorically deny all responsibility for all that has ever, or will ever happen. Our innocence is therefore wholly beyond doubt and absolutely unimpeachable, and so cannot, under even the remotest or unlikeliest circumstances, be brought into question. By clicking either on a link on this site, clicking on a link that leads to this site, or by arriving at this site by natural or supernatural means, you are in effect accepting responsibility for the fact that it is all entirely your own fault, down to the most miniscule detail, and that you are wholly accountable for whatever outcome may arise as a consequence of the aforementioned action or actions insofar as they were undertaken personally by you on an entirely voluntary basis and without any persuasion, coercion or influence from any party or parties other than yourself. Don't come sniveling to us, we are only figments of your imagination. I also agree that if I am ever with a contributor to this website during mealtimes I agree to pay for any super-sizing of their meal, or at least a nice dessert or one of those foo-foo drinks with an umbrella or a monkey. By admitting to have seen the worthless spineless drivel on this website (also known as content)

I Agree Wholeheartedly and Without Reservation to the above. (Except maybe for that part about the monkey.)

All Your Base Are Belong To Us.

Soylent Green Is People!

Never make a bet with a Sicilian when Death is on the Line!

No. Really, I do agree.