PT-2004-1306 · Microsoft · Virtual Pc
Published
2004-03-03
·
Updated
2018-10-12
·
CVE-2004-0115
CVSS v2.0
4.6
Medium
| Vector | AV:L/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Microsoft Virtual PC for Mac versions 6.0 through 6.1
Description
The issue allows local attackers to truncate and overwrite arbitrary files and execute arbitrary code via a symlink attack on the VPCServices Log temporary file.
Recommendations
For versions 6.0 through 6.1, update to a version that contains a fix for this issue to prevent local attackers from executing arbitrary code.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Virtual Pc