MS06-065: Remote Code Excution in Windows Object Packager

Published: 2006-10-10
Last Updated: 2006-10-10 18:59:47 UTC
by John Bambenek (Version: 1)
0 comment(s)
There exists a remote code execution vulnerability in Windows Object Packager (MS06-065) due to the way the application handles file extensions. A specially crafted file could be created that would execute code if a user was sent to a malicious website. However, there is quite a bit of user interaction required for this exploit to actually work. Enhanced Security Configuration for Windows 2003 will effectively mitigate this problem.

The CVE for this exploit is CVE-2006-4692 and will not likely see much action in the wild.
0 comment(s)


Diary Archives