|
|
|
![]() |
Vulnerability Note VU#616200Microsoft Windows Shell contains a buffer overflowOverviewA remotely exploitable buffer overflow vulnerability exists in the Microsoft Windows Shell.I. DescriptionThe Microsoft Windows Shell provides the basic human-computer interface for Windows systems. Microsoft describes the Shell as follows:The Windows Shell is responsible for providing the basic framework of the Windows user interface experience. It is most familiar to users as the Windows Desktop, but also provides a variety of other functions to help define the user's computing session, including organizing files and folders, and providing the means to start applications. A buffer overflow exists in the process the Windows Shell uses to launch applications. If an attacker can persuade a user to visit a specially crafted web page the attacker may be able to execute arbitrary code with the privileges of the current user. For more detailed information and for a list of vulnerable software, see Microsoft Security Bulletin MS04-037. Please also note that this advisory replaces MS04-024 for Microsoft Windows NT 4.0, 2000, XP, and Server 2003.
References
Microsoft has published Microsoft Security Bulletin MS04-037 to address this vulnerability.
This document was written by Jeff Gennari.
If you have feedback, comments, or additional information about this vulnerability, please send us
email. |
|||||||||||||||||||||||||||||||||||||
|
|||||||||||||||||||||||||||||||||||||||