Vulnerability Name: | CVE-2000-0160 (CCN-4035) | ||||||||
Assigned: | 2000-02-19 | ||||||||
Published: | 2000-02-19 | ||||||||
Updated: | 2021-07-22 | ||||||||
Summary: | The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attacker to install software components without prompting the user by stating that the software's manufacturer is Microsoft. | ||||||||
CVSS v3 Severity: | 9.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 7.6 High (CVSS v2 Vector: AV:N/AC:H/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Configuration | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Mon Feb 21 2000 - 12:39:38 CST Microsoft signed software can be install software without prompting users Source: MITRE Type: CNA CVE-2000-0160 Source: CCN Type: CIAC Information Bulletin K-057 Microsoft "Active Setup Download" Vulnerability Source: CCN Type: Microsoft Security Bulletin MS00-042 FAQ Microsoft Security Bulletin (MS00-042):Frequently Asked Questions Source: CCN Type: Microsoft Security Bulletin MS00-042 Patch Available for 'Active Setup Download' Vulnerability Source: CCN Type: OSVDB ID: 7901 Microsoft IE Active Setup ActiveX Component Arbitrary Software Installation Source: CCN Type: BID-999 Microsoft Signed ActiveX Active Setup Vulnerability Source: BUGTRAQ Type: UNKNOWN 20000221 Microsoft signed software can be install software without prompting users Source: XF Type: UNKNOWN win-active-setup(4035) Source: CCN Type: Microsoft Knowledge Base Article 265258 Patch Available for "Active Setup Download" Vulnerability in Internet Explorer (Q265258) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |