PT-2004-1806 · Microsoft · Windows 2000+1

Published

2004-07-23

·

Updated

2019-04-30

·

CVE-2004-0726

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Microsoft Windows 2000
Description The issue allows remote attackers to execute arbitrary script in the local computer zone. This is achieved via an ASX filename that contains javascript, which is executed in the local context in a preview panel.
Recommendations For Microsoft Windows 2000, consider disabling the Windows Media Player control as a temporary workaround until a patch is available. Restrict access to potentially malicious ASX files to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2004-0726

Affected Products

Windows 2000
Windows Media Player