Code Execution Vulnerability in Windows Script Engine - 20 Mar 2003

A new vulnerability in the Windows Script Engine can result in the execution of arbitrary code on the vulnerable system.

Ken Pfeil

March 19, 2003

3 Min Read
ITPro Today logo

ReportedMarch 19, 2003, by Microsoft.

                       

 

VERSIONS AFFECTED

 

·        Windows XP

·        Windows 2000

·        Windows Me

·        Windows 98 Second Edition

·        Windows 98

·        Windows NT 4.0

·        Windows NT Server 4.0, Terminal Server Edition

 

DESCRIPTION

 

Anew vulnerability in the Windows Script Engine can result in the execution ofarbitrary code on the vulnerable system. This vulnerability stems from a flawin the way the Windows Script Engine for JScript processes information. Toexploit the vulnerability, and attacker could construct a Web page that, whenvisited by the user, would use the user’s privileges to execute code of theattacker’s choice. The attacker could host the Web on a Web site or email itdirectly to the user.

 

VENDOR RESPONSE

 

Microsofthas released Security Bulletin MS03-008,“Flaw in WindowsScript Engine Could Allow Code Execution (814078),” to address this vulnerabilityand recommends that affected users immediately apply the appropriate patchmentioned in the bulletin.

 

CREDIT

Discoveredby RolandPostle.

Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like