Oval Definition:oval:org.mitre.oval:def:185
Revision Date:2011-05-16Version:48
Title:Automatic ActiveX Approval on WinXP Low Memory
Description:The Authenticode capability in Microsoft Windows NT through Server 2003 does not prompt the user to download and install ActiveX controls when the system is low on memory, which could allow remote attackers execute arbitrary code without user approval.
Family:windowsClass:vulnerability
Status:ACCEPTEDReference(s):CVE-2003-0660
Platform(s):Microsoft Windows XP
Product(s):Authenticode
Definition Synopsis
  • Software section
  • a vulnerable version of cryptui.dll exists
  • no service pack is installed and cryptui.dll is less than 5.131.2600.117
  • NOT Win2K/XP/2003 is patched
  • AND the version of cryptui.dll is less than 5.131.2600.117
  • OR service pack 1 is installed and cryptui.dll is less than 5.131.2600.1243
  • Win2K/XP/2003/Vista service pack 1 is installed
  • AND the version of cryptui.dll is less than 5.131.2600.1243
  • AND NOT Patch WindowsXP-KB823182-x86-ENU Installed
  • AND Windows XP (sp1 or earlier) is installed
  • Windows XP is installed
  • AND NOT Win2K/XP/2003 service pack 2 (or later) is installed
  • AND Configuration section
  • downloading of signed ActiveX controls is enabled
  • current user settings are being used and the downloading of signed ActiveX controls is enabled
  • NOT use machine settings rather than individual user settings
  • AND downloading of signed ActiveX controls is enabled for the local machine
  • AND local machine settings are being used and the downloading of signed ActiveX controls is enabled
  • use machine settings rather than individual user settings
  • AND downloading of signed ActiveX controls is enabled for the current user
  • BACK