CVE-2004-0726

Windows 2000 - Remote Code Execution via ASX Filename with JavaScript

Title source: llm
STIX 2.1

Description

The Windows Media Player control in Microsoft Windows 2000 allows remote attackers to execute arbitrary script in the local computer zone via an ASX filename that contains javascript, which is executed in the local context in a preview panel.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16704
Exploit, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/10693
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=108965512912175&w=2

Scores

EPSS 0.1142
EPSS Percentile 95.6%

Details

Status published
Products (1)
microsoft/windows_2000 (5 CPE variants)
Published Jul 27, 2004
Tracked Since Feb 18, 2026