Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2000-0790

Overview

Vulnerability Score 4.6 4.6
CVE Id CVE-2000-0790
Last Modified 05 Sep 2008 04:21:53
Published 20 Oct 2000 12:00:00
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector LOCAL
Access Complexity LOW
Authentication NONE

CVE-2000-0790

Summary

The web-based folder display capability in Microsoft Internet Explorer 5.5 on Windows 98 allows local users to insert Trojan horse programs by modifying the Folder.htt file and using the InvokeVerb method in the ShellDefView ActiveX control to specify a default execute option for the first file that is listed in the folder.

Vulnerable Systems

Operating System

  • Microsoft Windows 2000

  • Microsoft Windows 98

  • Microsoft Windows 98se


References

BUGTRAQ - 20000828 IE 5.5/5.x for Win98 may execute arbitrary files that can be accessed thru Microsoft Networking. Also local Administrator compromise at least on default Windows 2000.

BID - 1571

XF - ie-folder-remote-exe(5097)


Last Updated: 27 May 2016 10:35:52