vendor:
Windows XP
by:
AzM
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: Windows XP
Affected Version From: Microsoft Windows Explorer 5.0
Affected Version To: Microsoft Windows Explorer 6.0
Patch Exists: Yes
Related CWE: BID 19365, BID 21992
CPE: o:microsoft:windows_xp
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2006
Microsoft Windows Explorer Denial of Service Vulnerability
Microsoft Windows Explorer is prone to a denial-of-service vulnerability. A remote attacker may exploit this vulnerability by presenting a malicious file to a victim user. Users do not have to open the file -- simply browsing a folder containing the malicious file is sufficient to trigger this issue. A successful exploit will crash the vulnerable application, effectively denying service.
Mitigation:
Ensure that all users are running the latest version of Microsoft Windows Explorer.