PT-2007-3038 · Microsoft · Windows Vista

Published

2007-03-24

·

Updated

2018-10-16

·

CVE-2007-1658

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Microsoft Windows Vista
Description: The issue allows remote attackers to execute certain programs via a link to a local file or UNC share pathname. This can occur when there is a directory with the same base name as an executable program at the same level. For example, this can be demonstrated using C:/windows/system32/winrm (winrm.cmd) and migwiz (migwiz.exe).
Recommendations: For Microsoft Windows Vista, consider restricting access to executable programs with the same base name as directories to minimize the risk of exploitation. As a temporary workaround, avoid using links to local files or UNC share pathnames that could lead to the execution of unintended programs. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-1658

Affected Products

Windows Vista