PT-2003-1786 · Microsoft · Windows Server 2003+2
Published
2003-10-17
·
Updated
2019-04-30
·
CVE-2003-0660
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
Microsoft Windows NT through Server 2003
Description:
The issue concerns the Authenticode capability, which fails to prompt the user to download and install ActiveX controls when the system is low on memory. This could allow remote attackers to execute arbitrary code without user approval.
Recommendations:
For Microsoft Windows NT through Server 2003, consider restricting the use of ActiveX controls until a fix is available. As a temporary workaround, ensure that systems have sufficient memory to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Activex
Windows Nt
Windows Server 2003