PT-2000-1722 · Microsoft · Internet Explorer
Publicado
2000-10-20
·
Atualizado
2017-10-10
·
CVE-2000-0790
CVSS v2.0
4.6
Média
| Vetor | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer version 5.5
Description
The issue allows local users to insert Trojan horse programs by modifying the Folder.htt file and using the
InvokeVerb method in the ShellDefView ActiveX control to specify a default execute option for the first file that is listed in the folder.Recommendations
For Microsoft Internet Explorer version 5.5, consider disabling the use of the
InvokeVerb method in the ShellDefView ActiveX control to minimize the risk of exploitation. Restrict access to the Folder.htt file to prevent unauthorized modifications.Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Internet Explorer