PT-2006-2484 · Microsoft · Internet Explorer+2

Published

2006-03-29

·

Updated

2018-10-18

·

CVE-2006-1476

CVSS v2.0

2.6

Low

VectorAV:N/AC:H/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Windows XP SP2
Description The issue allows local user-assisted users to potentially trick a user into unblocking a Trojan horse program. This occurs when the Windows Firewall in Microsoft Windows produces incorrect application block alerts for an application filename that is ".exe" with no preceding characters. A malicious ".exe" program placed in a folder with a name like "Internet Explorer" could trigger a prompt about unblocking the "Internet Explorer" program, leading to potential security risks.
Recommendations For Windows XP SP2, consider implementing additional security measures to verify the authenticity and safety of programs before unblocking them, especially when the application filename is ".exe" and placed in folders with names that could be misleading or appear as trusted applications.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2006-1476

Affected Products

Internet Explorer
Windows Firewall
Windows Xp Sp2