PT-2002-1717 · Microsoft · Windows Nt 4.0+6
Publicado
2002-10-10
·
Atualizado
2019-04-30
·
CVE-2002-0694
CVSS v2.0
7.5
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions prior to the fix, including 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP
Description
The issue concerns the HTML Help facility in Microsoft Windows. It allows remote attackers to execute arbitrary code via HTML mail that references or inserts a malicious .chm file containing shortcuts that can be executed.
Recommendations
For Microsoft Windows 98, 98 Second Edition, Millennium Edition, NT 4.0, NT 4.0 Terminal Server Edition, Windows 2000, and Windows XP, apply the fix provided by Microsoft to resolve the issue.
As a temporary workaround, consider restricting the execution of .chm files from the Temporary Internet Files folder to minimize the risk of exploitation.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Windows 2000
Windows 98
Windows 98 Second Edition
Windows Millennium Edition
Windows Nt 4.0
Windows Nt 4.0 Terminal Server Edition
Windows Xp