Subscribe to Windows IT Pro
March 20, 2003 12:00 AM

Code Execution Vulnerability in Windows Script Engine

Windows IT Pro
InstantDoc ID #38384
Rating: (0)

Reported March 19, 2003, by Microsoft.

                       

 

VERSIONS AFFECTED

 

·         Windows XP

·         Windows 2000

·         Windows Me

·         Windows 98 Second Edition

·         Windows 98

·         Windows NT 4.0

·         Windows NT Server 4.0, Terminal Server Edition

 

DESCRIPTION

 

A new vulnerability in the Windows Script Engine can result in the execution of arbitrary code on the vulnerable system. This vulnerability stems from a flaw in the way the Windows Script Engine for JScript processes information. To exploit the vulnerability, and attacker could construct a Web page that, when visited by the user, would use the user’s privileges to execute code of the attacker’s choice. The attacker could host the Web on a Web site or email it directly to the user.

 

VENDOR RESPONSE

 

Microsoft has released Security Bulletin MS03-008, “Flaw in Windows Script Engine Could Allow Code Execution (814078),” to address this vulnerability and recommends that affected users immediately apply the appropriate patch mentioned in the bulletin.

 

CREDIT

Discovered by Roland Postle.

Related Content:

ARTICLE TOOLS

Comments
    There are no comments to display. Be the first one!
You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.