PT-2006-2484 · Microsoft · Internet Explorer+2
Publicado
2006-03-29
·
Atualizado
2018-10-18
·
CVE-2006-1476
CVSS v2.0
2.6
Baixa
| Vetor | AV:N/AC:H/Au:N/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Windows XP SP2
Description
The issue allows local user-assisted users to potentially trick a user into unblocking a Trojan horse program. This occurs when the Windows Firewall in Microsoft Windows produces incorrect application block alerts for an application filename that is ".exe" with no preceding characters. A malicious ".exe" program placed in a folder with a name like "Internet Explorer" could trigger a prompt about unblocking the "Internet Explorer" program, leading to potential security risks.
Recommendations
For Windows XP SP2, consider implementing additional security measures to verify the authenticity and safety of programs before unblocking them, especially when the application filename is ".exe" and placed in folders with names that could be misleading or appear as trusted applications.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Internet Explorer
Windows Firewall
Windows Xp Sp2