CVE-2009-0243: High severity Microsoft Windows 2000 vulnerability
Microsoft Windows does not properly enforce the Autorun and NoDriveTypeAutoRun registry values, which allows physically proximate attackers to execute arbitrary code by (1) inserting CD-ROM media, (2) inserting DVD media, (3) connecting a USB device, and (4) connecting a Firewire device; (5) allows user-assisted remote attackers to execute arbitrary code by mapping a network drive; and allows user-assisted attackers to execute arbitrary code by clicking on (6) an icon under My Computer\Devices with Removable Storage and (7) an option in an AutoPlay dialog, related to the Autorun.inf file. NOTE: vectors 1 and 3 on Vista are already covered by CVE-2008-0951.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Set the Autorun and NoDriveTypeAutoRun registry values to disable AutoRun/AutoPlay so that Autorun.inf on CD-ROM, DVD, USB, Firewire, and mapped network drives is not executed. Apply this registry configuration on affected Windows 2000, Windows Server, Windows Vista, and Windows XP systems.
Microsoft Windows (Windows 2000, Windows Server, Windows Vista, Windows XP) Autorun and NoDriveTypeAutoRun (registry values) = disabled
Event History
Frequently Asked Questions
What is the severity of CVE-2009-0243?
CVE-2009-0243 is classified as a critical vulnerability that allows arbitrary code execution.
How do I fix CVE-2009-0243?
To address CVE-2009-0243, ensure that your operating system is updated with the latest security patches from Microsoft.
Which operating systems are affected by CVE-2009-0243?
CVE-2009-0243 affects Microsoft Windows 2000, Windows XP, Windows Vista, Windows Server 2003, and Windows Server 2008.
What types of attacks can exploit CVE-2009-0243?
CVE-2009-0243 can be exploited through physical access to the system via malicious media like CD-ROMs, DVDs, USB devices, or Firewire connections.
Is there a workaround for CVE-2009-0243?
Disabling Autorun and NoDriveTypeAutoRun features in the registry settings may serve as a temporary workaround for CVE-2009-0243.