vendor:
Windows 2000
by:
nop
7.5
CVSS
HIGH
Memory-corruption
119
CWE
Product Name: Windows 2000
Affected Version From: Microsoft Windows 2000
Affected Version To: Microsoft Windows 2000
Patch Exists: NO
Related CWE: N/A
CPE: o:microsoft:windows_2000
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2005
Microsoft Windows 2000 Multiple COM Object Instantiation Vulnerability
Microsoft Windows 2000 is prone to multiple memory-corruption vulnerabilities that are related to the instantiation of COM objects. These issues may be remotely triggered through Internet Explorer. The vulnerabilities arise because of the way Internet Explorer tries to instantiate certain COM objects as ActiveX controls. This may result in arbitrary code execution, but this has not been confirmed.
Mitigation:
Ensure that all COM objects are properly instantiated and that only trusted objects are allowed to be instantiated.