First published: Thu May 20 2004(Updated: )
The showHelp function in Internet Explorer 6 on Windows XP Pro allows remote attackers to execute arbitrary local .CHM files via a double backward slash ("\\") before the target CHM file, as demonstrated using an "ms-its" URL to ntshared.chm. NOTE: this bug may overlap CVE-2003-1041.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Internet Explorer | =6.0-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-0475 is considered a high severity vulnerability due to its potential for remote exploitation.
To mitigate CVE-2004-0475, it is recommended to upgrade Internet Explorer to a later version that is not affected by this vulnerability.
CVE-2004-0475 allows attackers to execute local CHM files, which can potentially lead to unauthorized access or execution of harmful scripts.
Yes, CVE-2004-0475 specifically affects Internet Explorer 6 on Windows XP Professional.
Yes, CVE-2004-0475 can be exploited using specially crafted URLs that invoke the vulnerability.