PT-2003-1513 · Microsoft · Windows Xp+1

At4R Insan3

·

Published

2003-05-17

·

Updated

2018-10-12

·

CVE-2003-0306

CVSS v2.0

7.2

High

VectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Windows XP
Description: A buffer overflow issue in EXPLORER.EXE allows attackers to execute arbitrary code as the XP user. This is achieved via a desktop.ini file with a long .ShellClassInfo parameter.
Recommendations: For Windows XP, consider restricting access to the desktop.ini file to minimize the risk of exploitation. As a temporary workaround, avoid using long .ShellClassInfo parameters in desktop.ini files until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0306

Affected Products

Explorer.Exe
Windows Xp