PT-2003-1786 · Microsoft · Windows Server 2003+2

Published

2003-10-17

·

Updated

2019-04-30

·

CVE-2003-0660

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: Microsoft Windows NT through Server 2003
Description: The issue concerns the Authenticode capability, which fails to prompt the user to download and install ActiveX controls when the system is low on memory. This could allow remote attackers to execute arbitrary code without user approval.
Recommendations: For Microsoft Windows NT through Server 2003, consider restricting the use of ActiveX controls until a fix is available. As a temporary workaround, ensure that systems have sufficient memory to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-0660

Affected Products

Activex
Windows Nt
Windows Server 2003