Vulnerability in Windows Shell Could Allow Remote Code Execution

A vulnerability exists in drag-and-drop events that could allow an intruder to write to? files on a user's system via malicious Web content. A successful exploit could let the intruder take complete control of a user's system.

ITPro Today

February 8, 2005

1 Min Read
ITPro Today logo in a gray background | ITPro Today

ReportedFebruary 8, 2005 by Microsoft

VERSIONS AFFECTED


DESCRIPTION

A vulnerability existsin drag-and-drop events that could allow an intruder to write to?files on a user's system via malicious Web content. A successfulexploit could let the intruder take complete control of a user'ssystem.

VENDOR RESPONSE

Microsoft has releasedSecurity Bulletin MS05-008, "Vulnerabilityin Windows Shell Could Allow Remote Code Execution (890047),"and a patch to correct the problem.





Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like