PT-2007-3038 · Microsoft · Windows Vista
Publicado
2007-03-24
·
Atualizado
2018-10-16
·
CVE-2007-1658
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Microsoft Windows Vista
Description:
The issue allows remote attackers to execute certain programs via a link to a local file or UNC share pathname. This can occur when there is a directory with the same base name as an executable program at the same level. For example, this can be demonstrated using C:/windows/system32/winrm (winrm.cmd) and migwiz (migwiz.exe).
Recommendations:
For Microsoft Windows Vista, consider restricting access to executable programs with the same base name as directories to minimize the risk of exploitation. As a temporary workaround, avoid using links to local files or UNC share pathnames that could lead to the execution of unintended programs. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Windows Vista