MS Windows Explorer and Internet Explorer CLSID文件执行漏洞

漏洞信息详情

MS Windows Explorer and Internet Explorer CLSID文件执行漏洞

漏洞简介

当Class ID (CLSID)在文件名末尾时,Internet Explorer 5.5版本不能显示。攻击者通过使文件成为安全文件类型诱骗用户执行危险程序。

漏洞公告

Currently the SecurityFocus staff are not aware of any vendor-supplied patches for this issue. If you feel we are in error or are aware of more recent information, please mail us at: vuldb@securityfocus.com .
@securityfocus.com>

参考网址

来源: XF
名称: ie-clsid-execute-files(6426)
链接:http://xforce.iss.net/static/6426.php

来源: BUGTRAQ
名称: 20010416 Double clicking on innocent looking files may be dangerous
链接:http://www.securityfocus.com/archive/1/176909

来源: www.sarc.com
链接:http://www.sarc.com/avcenter/venc/data/vbs.postcard@mm.html

来源: vil.nai.com
链接:http://vil.nai.com/vil/virusSummary.asp?virus_k=99048

来源: BID
名称: 2612
链接:http://www.securityfocus.com/bid/2612

来源: OSVDB
名称: 7858
链接:http://www.osvdb.org/7858

来源: www.guninski.com
链接:http://www.guninski.com/clsidext.html

受影响实体

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享