Vulnerabilities > CVE-2006-0012 - Unspecified vulnerability in Microsoft products
Attack vector
UNKNOWN Attack complexity
UNKNOWN Privileges required
UNKNOWN Confidentiality impact
UNKNOWN Integrity impact
UNKNOWN Availability impact
UNKNOWN microsoft
nessus
Summary
Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."
Vulnerable Configurations
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS06-015.NASL |
description | The remote version of Windows contains a version of the Windows Explorer that has a vulnerability in the way it handles COM objects. An attacker could exploit this vulnerability by asking a victim to visit a rogue website containing a malformed COM object. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 21212 |
published | 2006-04-11 |
reporter | This script is Copyright (C) 2006-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/21212 |
title | MS06-015: Vulnerabilities in Windows Explorer Could Allow Remote Code Execution (908531) |
code |
|
Oval
accepted 2011-05-16T04:00:30.217-04:00 class vulnerability contributors name Robert L. Hollis organization ThreatGuard, Inc. name Anna Min organization BigFix, Inc name Shane Shaffer organization G2, Inc. name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc.
description Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability." family windows id oval:org.mitre.oval:def:1191 status accepted submitted 2006-04-12T12:55:00.000-04:00 title Win2K COM object Remote Code Execution Vulnerability version 69 accepted 2011-05-16T04:01:01.788-04:00 class vulnerability contributors name Robert L. Hollis organization ThreatGuard, Inc. name Dragos Prisaca organization Gideon Technologies, Inc. name Shane Shaffer organization G2, Inc. name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc.
description Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability." family windows id oval:org.mitre.oval:def:1448 status accepted submitted 2006-04-12T12:55:00.000-04:00 title WinXP,SP2 COM object Remote Code Execution Vulnerability version 69 accepted 2011-05-16T04:01:34.633-04:00 class vulnerability contributors name Robert L. Hollis organization ThreatGuard, Inc. name Shane Shaffer organization G2, Inc. name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc.
description Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability." family windows id oval:org.mitre.oval:def:1679 status accepted submitted 2006-04-12T12:55:00.000-04:00 title WinXP,SP1 COM object Remote Code Execution Vulnerability version 68 accepted 2011-05-16T04:01:43.037-04:00 class vulnerability contributors name Robert L. Hollis organization ThreatGuard, Inc. name Shane Shaffer organization G2, Inc. name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc.
description Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability." family windows id oval:org.mitre.oval:def:1743 status accepted submitted 2006-04-12T12:55:00.000-04:00 title Windows (S03/64-bit XP) COM object Remote Code Execution Vulnerability version 68 accepted 2011-05-16T04:01:44.830-04:00 class vulnerability contributors name Robert L. Hollis organization ThreatGuard, Inc. name Jonathan Baker organization The MITRE Corporation name Shane Shaffer organization G2, Inc. name Sudhir Gandhe organization Telos name Shane Shaffer organization G2, Inc.
description Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability." family windows id oval:org.mitre.oval:def:1764 status accepted submitted 2006-04-12T12:55:00.000-04:00 title Server 2003 COM object Remote Code Execution Vulnerability version 69
References
- http://www.us-cert.gov/cas/techalerts/TA06-101A.html
- http://www.securityfocus.com/bid/17464
- http://secunia.com/advisories/19606
- http://www.kb.cert.org/vuls/id/641460
- http://www.osvdb.org/24516
- http://securitytracker.com/id?1015897
- http://www.vupen.com/english/advisories/2006/1320
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25554
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1764
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1743
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1679
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1448
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1191
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-015