PT-2002-1717 · Microsoft · Windows Nt 4.0+6

Publicado

2002-10-10

·

Atualizado

2019-04-30

·

CVE-2002-0694

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Windows versions prior to the fix, including 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP
Description The issue concerns the HTML Help facility in Microsoft Windows. It allows remote attackers to execute arbitrary code via HTML mail that references or inserts a malicious .chm file containing shortcuts that can be executed.
Recommendations For Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP, apply the fix provided by Microsoft to resolve the issue. As a temporary workaround, consider restricting the execution of .chm files from the Temporary Internet Files folder to minimize the risk of exploitation.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2002-0694

Produtos afetados

Windows 2000
Windows 98
Windows 98 Second Edition
Windows Millennium Edition
Windows Nt 4.0
Windows Nt 4.0 Terminal Server Edition
Windows Xp