First published: Wed Mar 29 2006(Updated: )
Windows Firewall in Microsoft Windows XP SP2 does not produce application alerts when an application is executed using the NTFS Alternate Data Streams (ADS) filename:stream syntax, which might allow local users to launch a Trojan horse attack in which the victim does not obtain the alert that Windows Firewall would have produced for a non-ADS file.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows XP | =sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2006-1475 has a medium severity due to its potential to allow Trojan horse attacks without alerts.
To mitigate CVE-2006-1475, consider upgrading to a later version of Windows that does not contain this vulnerability.
CVE-2006-1475 primarily affects users of Microsoft Windows XP SP2.
CVE-2006-1475 enables local users to execute applications without triggering Windows Firewall alerts.
No, CVE-2006-1475 is a local vulnerability requiring physical access to the system.