CVE-2006-1476: Low severity Microsoft Windows XP vulnerability
Windows Firewall in Microsoft Windows XP SP2 produces incorrect application block alerts when the application filename is ".exe" (with no characters before the "."), which might allow local user-assisted users to trick a user into unblocking a Trojan horse program, as demonstrated by a malicious ".exe" program in a folder named "Internet Explorer," which triggers a question about whether to unblock the "Internet Explorer" program.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1476?
The severity of CVE-2006-1476 is considered moderate due to the potential for user-assisted exploitation.
How do I fix CVE-2006-1476?
To fix CVE-2006-1476, it is recommended to apply any available security updates for Microsoft Windows XP.
Who is affected by CVE-2006-1476?
CVE-2006-1476 affects users of Microsoft Windows XP Service Pack 2, particularly those using the Tablet PC edition.
What kind of attacks can CVE-2006-1476 facilitate?
CVE-2006-1476 can facilitate attacks that trick users into unblocking malicious applications by exploiting incorrect application block alerts.
Is user interaction required for CVE-2006-1476 to be exploited?
Yes, user interaction is required for CVE-2006-1476 to be successfully exploited, as it involves user assistance to unblock the Trojan horse.