PT-2007-3038 · Microsoft · Windows Vista

Publicado

2007-03-24

·

Atualizado

2018-10-16

·

CVE-2007-1658

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Microsoft Windows Vista
Description: The issue allows remote attackers to execute certain programs via a link to a local file or UNC share pathname. This can occur when there is a directory with the same base name as an executable program at the same level. For example, this can be demonstrated using C:/windows/system32/winrm (winrm.cmd) and migwiz (migwiz.exe).
Recommendations: For Microsoft Windows Vista, consider restricting access to executable programs with the same base name as directories to minimize the risk of exploitation. As a temporary workaround, avoid using links to local files or UNC share pathnames that could lead to the execution of unintended programs. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2007-1658

Produtos afetados

Windows Vista