Code Execution Vulnerability in Windows Script Engine - 20 Mar 2003
A new vulnerability in the Windows Script Engine can result in the execution of arbitrary code on the vulnerable system.
March 19, 2003
ReportedMarch 19, 2003, by Microsoft.
VERSIONS AFFECTED
· Windows XP
· Windows 2000
· Windows Me
· Windows 98 Second Edition
· Windows 98
· Windows NT 4.0
· Windows NT Server 4.0, Terminal Server Edition
DESCRIPTION
Anew vulnerability in the Windows Script Engine can result in the execution ofarbitrary code on the vulnerable system. This vulnerability stems from a flawin the way the Windows Script Engine for JScript processes information. Toexploit the vulnerability, and attacker could construct a Web page that, whenvisited by the user, would use the user’s privileges to execute code of theattacker’s choice. The attacker could host the Web on a Web site or email itdirectly to the user.
VENDOR RESPONSE
Microsofthas released Security Bulletin MS03-008,“Flaw in WindowsScript Engine Could Allow Code Execution (814078),” to address this vulnerabilityand recommends that affected users immediately apply the appropriate patchmentioned in the bulletin.
CREDIT
Discoveredby RolandPostle.
About the Author
You May Also Like