PT-2006-2484 · Microsoft · Internet Explorer+2

Publicado

2006-03-29

·

Atualizado

2018-10-18

·

CVE-2006-1476

CVSS v2.0

2.6

Baixa

VetorAV:N/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Windows XP SP2
Description The issue allows local user-assisted users to potentially trick a user into unblocking a Trojan horse program. This occurs when the Windows Firewall in Microsoft Windows produces incorrect application block alerts for an application filename that is ".exe" with no preceding characters. A malicious ".exe" program placed in a folder with a name like "Internet Explorer" could trigger a prompt about unblocking the "Internet Explorer" program, leading to potential security risks.
Recommendations For Windows XP SP2, consider implementing additional security measures to verify the authenticity and safety of programs before unblocking them, especially when the application filename is ".exe" and placed in folders with names that could be misleading or appear as trusted applications.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2006-1476

Produtos afetados

Internet Explorer
Windows Firewall
Windows Xp Sp2