Vulnerability Name:

CVE-2006-1475 (CCN-25597)

Assigned:2006-03-24
Published:2006-03-24
Updated:2018-10-18
Summary:Windows Firewall in Microsoft Windows XP SP2 does not produce application alerts when an application is executed using the NTFS Alternate Data Streams (ADS) filename:stream syntax, which might allow local users to launch a Trojan horse attack in which the victim does not obtain the alert that Windows Firewall would have produced for a non-ADS file.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:2.1 Low (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-Other
Vulnerability Consequences:Bypass Security
References:Source: CCN
Type: BugTraq Mailing List, Fri Mar 24 2006 - 04:34:46 CST
Microsoft Windows XP SP2 Firewall issue

Source: MITRE
Type: CNA
CVE-2006-1475

Source: CCN
Type: OSVDB ID: 31799
Windows Firewall ADS Application Alert Failure

Source: BUGTRAQ
Type: UNKNOWN
20060324 Microsoft Windows XP SP2 Firewall issue

Source: BUGTRAQ
Type: UNKNOWN
20060327 Re: Microsoft Windows XP SP2 Firewall issue

Source: XF
Type: UNKNOWN
winxp-firewall-ads-bypass(25597)

Source: XF
Type: UNKNOWN
winxp-firewall-ads-bypass(25597)

Vulnerable Configuration:Configuration 1:
  • cpe:/o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:microsoft:windows:xp:sp2:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    microsoft windows xp * sp2
    microsoft windows xp sp2