First published: Fri Dec 31 2004(Updated: )
Microsoft Windows XP Explorer allows local users to execute arbitrary code via a system folder with a Desktop.ini file containing a .ShellClassInfo specifier with a CLSID value that is associated with an executable file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows XP | =sp1 | |
Microsoft Windows XP | =gold | |
Microsoft Windows XP |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2004-2289 is considered to have a medium severity level due to its ability to allow local users to execute arbitrary code.
To fix CVE-2004-2289, ensure your Windows XP installation is updated with all available security patches from Microsoft.
CVE-2004-2289 affects local users on Microsoft Windows XP systems, specifically those running SP1 or the original release version.
CVE-2004-2289 can facilitate unauthorized execution of executables via manipulation of a Desktop.ini file.
CVE-2004-2289 affects Microsoft Windows XP in its initial release and SP1.