PT-2002-2484 · Oracle+1 · Java+2
Publicado
2002-12-31
·
Atualizado
2017-07-11
·
CVE-2002-1762
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Microsoft Baseline Security Analyzer (MBSA) version 1.0
Description
The issue allows remote attackers to obtain sensitive system information due to the storage of security scans in plaintext at a known location, C:Documents and SettingsusernameSecurityScans. This could be exploited via malicious active content, such as ActiveX controls or Java.
Recommendations
For Microsoft Baseline Security Analyzer (MBSA) version 1.0, consider restricting access to the C:Documents and SettingsusernameSecurityScans directory to minimize the risk of exploitation. As a temporary workaround, avoid using active content such as ActiveX controls or Java until a more secure solution is implemented. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Activex
Java
Baseline Security Analyzer