vendor:
Windows HTA (HTML Application)
by:
Mohammad Reza Espargham
9.3
CVSS
HIGH
Remote Code Execution
94
CWE
Product Name: Windows HTA (HTML Application)
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: YES
Related CWE: MS14-064
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7 / Server 2008
2014
Microsoft Windows HTA (HTML Application) – Remote Code Execution
A remote code execution vulnerability exists in Microsoft Windows HTA (HTML Application) due to improper validation of user-supplied input. An attacker could exploit this vulnerability by convincing a user to open a specially crafted HTA file. Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code in the context of the current user.
Mitigation:
Microsoft has released a security update to address this vulnerability. Users are advised to apply the necessary update.