CVE-2000-0160: High severity Microsoft Internet Explorer vulnerability
The Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x allows a remote attacker to install software components without prompting the user by stating that the software's manufacturer is Microsoft.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
Microsoft Active Setup ActiveX componentfrom your environment.Uninstall or remove the Microsoft Active Setup ActiveX component from systems running Internet Explorer 4.x or 5.x if it is not required.
- Configuration
In Internet Explorer, disable the Microsoft Active Setup ActiveX component or configure the browser's security settings to always prompt before installing ActiveX controls to prevent silent installations.
Microsoft Active Setup ActiveX component (Internet Explorer 4.x/5.x) ActiveX installation / prompt behavior = disabled or prompt
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0160?
CVE-2000-0160 is considered a high severity vulnerability due to its potential to allow remote attackers to install software without user consent.
How do I fix CVE-2000-0160?
To fix CVE-2000-0160, users should upgrade to a more recent version of Internet Explorer or apply relevant security patches provided by Microsoft.
What software is affected by CVE-2000-0160?
CVE-2000-0160 affects Microsoft Internet Explorer versions 4.x and 5, as well as certain versions of Microsoft Outlook.
Can CVE-2000-0160 be exploited remotely?
Yes, CVE-2000-0160 can be exploited remotely by attackers to install harmful software without user permission.
What should I do if I am still using Internet Explorer 4.x or 5.x?
If you are still using Internet Explorer 4.x or 5.x, it is strongly recommended to upgrade your browser to a more secure version to mitigate the risks associated with CVE-2000-0160.