Vulnerabilities > CVE-2005-1214 - Unspecified vulnerability in Microsoft products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page.
Vulnerable Configurations
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS05-032.NASL |
description | The remote version of Windows contains a flaw in the Microsoft Agent service that could allow an attacker to spoof the content of a website. To exploit this flaw, an attacker would need to set up a rogue website and lure a victim on the remote host into visiting it. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 18485 |
published | 2005-06-14 |
reporter | This script is Copyright (C) 2005-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/18485 |
title | MS05-032: Vulnerability in Microsoft Agent Could Allow Spoofing (890046) |
code |
|
Oval
accepted 2011-05-16T04:00:30.901-04:00 class vulnerability contributors name Harvey Rubinovitz organization The MITRE Corporation name Harvey Rubinovitz organization The MITRE Corporation name Matthew Wojcik organization The MITRE Corporation name Dragos Prisaca organization Secure Elements, Inc. name Dragos Prisaca organization Gideon Technologies, Inc. name Shane Shaffer organization G2, Inc. name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc.
description Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page. family windows id oval:org.mitre.oval:def:1194 status accepted submitted 2005-06-22T12:00:00.000-04:00 title Microsoft Agent Security Prompt Spoofing Vulnerability (Windows XP) version 34 accepted 2011-05-16T04:03:20.482-04:00 class vulnerability contributors name Harvey Rubinovitz organization The MITRE Corporation name Harvey Rubinovitz organization The MITRE Corporation name Matthew Wojcik organization The MITRE Corporation name Shane Shaffer organization G2, Inc. name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc.
description Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page. family windows id oval:org.mitre.oval:def:682 status accepted submitted 2005-06-22T12:00:00.000-04:00 title Microsoft Agent Security Prompt Spoofing Vulnerability (Windows 2000) version 31 accepted 2011-05-16T04:03:35.415-04:00 class vulnerability contributors name Harvey Rubinovitz organization The MITRE Corporation name Harvey Rubinovitz organization The MITRE Corporation name Matthew Wojcik organization The MITRE Corporation name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc.
description Microsoft Agent allows remote attackers to spoof trusted Internet content and execute arbitrary code by disguising security prompts on a malicious Web page. family windows id oval:org.mitre.oval:def:906 status accepted submitted 2005-06-22T12:00:00.000-04:00 title Microsoft Agent Security Prompt Spoofing Vulnerability (Server 2003) version 30
References
- http://secunia.com/advisories/15689
- http://www.securityfocus.com/bid/13948
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A906
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A682
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1194
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-032