|
Family: Windows : Microsoft Bulletins --> Category: infos
Vulnerability in Windows Explorer Could Allow Remote Code Execution (921398) Vulnerability Scan
Vulnerability Scan Summary Acertains the presence of update 921398
Detailed Explanation for this Vulnerability Test
Synopsis :
Arbitrary code can be executed on the remote host through the web or
email client.
Description :
The remote host is running a version of Windows which contains a flaw
in the Windows Explorer Drag & Drop handler.
A possible hacker may be able to execute arbitrary code on the remote host
by constructing a malicious script and enticing a victim to visit a
web site or view a specially-crafted email message and save a file.
Solution :
Microsoft has released a set of patches for Windows 2000, XP and 2003 :
http://www.microsoft.com/technet/security/Bulletin/MS06-045.mspx
Threat Level:
Medium / CVSS Base Score : 5.6
(AV:R/AC:H/Au:NR/C:P/I:P/A:P/B:N)
Click HERE for more information and discussions on this network vulnerability scan.
|