First published: Wed Mar 01 2000(Updated: )
The window.showHelp() method in Internet Explorer 5.x does not restrict HTML help files (.chm) to be executed from the local host, which allows remote attackers to execute arbitrary commands via Microsoft Networking.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Internet Explorer | =5.0 | |
Internet Explorer | =5.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2000-0201 is considered a high-severity vulnerability due to its potential for remote command execution.
To fix CVE-2000-0201, it is recommended to upgrade to a newer version of Internet Explorer that does not have this vulnerability.
CVE-2000-0201 specifically affects Internet Explorer 5.0 and 5.01 versions.
Yes, CVE-2000-0201 can be exploited remotely, allowing attackers to execute arbitrary commands on the affected system.
A possible workaround for CVE-2000-0201 is to disable the use of the window.showHelp() method or to limit the execution of local help files.