PT-2006-2483 · Microsoft · Windows Xp Sp2+2

Published

2006-03-29

·

Updated

2018-10-18

·

CVE-2006-1475

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Windows XP SP2
Description The issue concerns the Windows Firewall in Microsoft Windows XP SP2, where it does not produce application alerts when an application is executed using the NTFS Alternate Data Streams (ADS) filename:stream syntax. This could allow local users to launch a Trojan horse attack without the victim receiving the alert that Windows Firewall would have produced for a non-ADS file. NTFS Alternate Data Streams (ADS) is a feature of the NTFS file system that allows multiple streams of data to be associated with a single file.
Recommendations For Windows XP SP2, consider disabling the use of NTFS Alternate Data Streams (ADS) to minimize the risk of exploitation, or apply specific configuration changes to the Windows Firewall to handle ADS executions appropriately. However, specific steps for these configurations are not provided. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1475

Affected Products

Ntfs
Windows Firewall
Windows Xp Sp2