First published: Tue Jan 25 2011(Updated: )
Microsoft Windows does not properly warn the user before enabling additional Human Interface Device (HID) functionality over USB, which allows user-assisted attackers to execute arbitrary programs via crafted USB data, as demonstrated by keyboard and mouse data sent by malware on a smartphone that the user connected to the computer.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2011-0638 has a medium severity rating, indicating a potential risk of user-assisted exploitation.
To mitigate CVE-2011-0638, ensure that your Windows operating system is updated with the latest security patches from Microsoft.
CVE-2011-0638 affects Microsoft Windows systems that interact with USB Human Interface Devices.
Disabling USB HID functionality on affected Windows systems may reduce the risk of CVE-2011-0638, but can also impact usability.
Yes, exploitation of CVE-2011-0638 requires user assistance, typically through the connection of a malicious USB device.