Oval Definition:oval:org.mitre.oval:def:1537
Revision Date:2011-05-16Version:46
Title:.lnk File-Open Remote Code Execution Vulnerability (Server 2003)
Description:Windows Shell for Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 allows remote attackers to execute arbitrary commands via a shortcut (.lnk) file with long font properties that lead to a buffer overflow in the Client/Server Runtime Server Subsystem (CSRSS), a different vulnerability than CVE-2005-2118.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2005-2122
Platform(s):Microsoft Windows Server 2003
Product(s):
Definition Synopsis
  • Windows Server 2003 is installed
  • AND NOT Win2K/XP/2003 is patched
  • AND shell32.dll is less than 6.0.3790.413
  • BACK