First published: Wed Apr 12 2006(Updated: )
Unspecified vulnerability in Windows Explorer in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote attackers to execute arbitrary code via attack vectors involving COM objects and "crafted files and directories," aka the "Windows Shell Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows XP | =sp1 | |
Microsoft Windows 2003 Server | =web | |
Microsoft Windows 2003 Server | =enterprise | |
Microsoft Windows 2003 Server | =enterprise_64-bit | |
Microsoft Windows XP | =gold | |
Microsoft Windows 2000 | ||
Microsoft Windows XP | ||
Microsoft Windows 2003 Server | =standard_64-bit | |
Microsoft Windows 2003 Server | =datacenter_64-bit-sp1 | |
Microsoft Windows 2000 | =sp4 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | ||
Microsoft Windows XP | =sp1 | |
Microsoft Windows 98SE | ||
Microsoft Windows 2000 | =sp2 | |
Microsoft Windows 2003 Server | =r2-sp1 | |
Microsoft Windows 2003 Server | =enterprise_64-bit-sp1 | |
Microsoft Windows 2003 Server | =r2 | |
Microsoft Windows 2003 Server | =web-sp1 | |
Microsoft Windows 2000 | =sp1 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | ||
Microsoft Windows 2003 Server | =standard-sp1 | |
Microsoft Windows Me | ||
Microsoft Windows 2003 Server | =enterprise-sp1 | |
Microsoft Windows 2003 Server | =standard | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows 98 | =gold | |
Microsoft Windows 2003 Server | =r2 | |
Microsoft Windows 2000 | =sp3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-0012 is classified as a critical vulnerability due to its potential to allow remote code execution.
To fix CVE-2006-0012, ensure that all affected Microsoft Windows versions are updated with the latest security patches from Microsoft.
CVE-2006-0012 affects Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Windows Server 2003 SP1.
CVE-2006-0012 can be exploited through specially crafted files and directories that manipulate COM objects.
While the vulnerability mainly affects outdated systems, any unpatched systems could still be at risk from exploitation of CVE-2006-0012.