Summary
There is a vulnerability in Authenticode that, under certain low memory conditions, could allow an ActiveX control to download and install without presenting the user with an approval dialog. To exploit this vulnerability, an attacker could host a malicious Web Site designed to exploit this vulnerability. If an attacker then persuaded a user to visit that site an ActiveX control could be installed and executed on the user's system. Alternatively, an attacker could create a specially formed HTML e-mail and send it to the user.
Exploiting the vulnerability would grant the attacker with the same privileges as the user.
Solution
see http://www.microsoft.com/technet/security/bulletin/ms03-041.mspx
Severity
Classification
-
CVE CVE-2003-0660 -
CVSS Base Score: 7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P
Related Vulnerabilities
- Microsoft Internet Explorer Multiple Memory Corruption Vulnerabilities (2879017)
- Microsoft Foundation Class (MFC) Library Remote Code Execution Vulnerability (2500212)
- Microsoft .NET Framework and Silverlight Remote Code Execution Vulnerability (2514842)
- Message Queuing Remote Code Execution Vulnerability (951071)
- Buffer Overrun in the ListBox and in the ComboBox (824141)