vendor:
Windows XP
by:
Not mentioned
7.5
CVSS
HIGH
Folder Automatic Execution
20
CWE
Product Name: Windows XP
Affected Version From: Microsoft Windows XP
Affected Version To: Unknown
Patch Exists: NO
Related CWE: Not mentioned
CPE: o:microsoft:windows_xp
Platforms Tested: Windows XP
Unknown
Microsoft Windows XP Folder Automatic Execution Vulnerability
A vulnerability in Windows Explorer allows for the automatic execution of executable content when a folder is accessed. This can be exploited by malicious actors to run code in the context of the logged-in user. Opening a folder is typically considered safe, making this vulnerability particularly dangerous. The issue can also be exploited remotely if the malicious folder is accessed from an SMB share. A proof-of-concept exploit has been provided that demonstrates the execution of NetMeeting and installation of a keylogger on a vulnerable system.
Mitigation:
No specific mitigation steps provided.