First published: Wed Jan 21 2009(Updated: )
Microsoft Windows does not properly enforce the Autorun and NoDriveTypeAutoRun registry values, which allows physically proximate attackers to execute arbitrary code by (1) inserting CD-ROM media, (2) inserting DVD media, (3) connecting a USB device, and (4) connecting a Firewire device; (5) allows user-assisted remote attackers to execute arbitrary code by mapping a network drive; and allows user-assisted attackers to execute arbitrary code by clicking on (6) an icon under My Computer\Devices with Removable Storage and (7) an option in an AutoPlay dialog, related to the Autorun.inf file. NOTE: vectors 1 and 3 on Vista are already covered by CVE-2008-0951.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 2000 | =sp4 | |
Microsoft Windows Server 2003 | ||
Microsoft Windows Server 2003 | =sp1 | |
Microsoft Windows Server 2003 | =sp1 | |
Microsoft Windows Server 2003 | =sp2 | |
Microsoft Windows Server 2008 Itanium | ||
Microsoft Windows Server 2008 Itanium | ||
Microsoft Windows Server 2008 Itanium | ||
Microsoft Windows Vista | ||
Microsoft Windows Vista | ||
Microsoft Windows Vista | =sp1 | |
Microsoft Windows XP | ||
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp2 | |
Microsoft Windows XP | =sp3 | |
Microsoft Windows Vista | =sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2009-0243 is classified as a critical vulnerability that allows arbitrary code execution.
To address CVE-2009-0243, ensure that your operating system is updated with the latest security patches from Microsoft.
CVE-2009-0243 affects Microsoft Windows 2000, Windows XP, Windows Vista, Windows Server 2003, and Windows Server 2008.
CVE-2009-0243 can be exploited through physical access to the system via malicious media like CD-ROMs, DVDs, USB devices, or Firewire connections.
Disabling Autorun and NoDriveTypeAutoRun features in the registry settings may serve as a temporary workaround for CVE-2009-0243.