Description
Internet Explorer on Windows XP does not properly modify the "Drag and Drop or copy and paste files" setting when the user sets it to "Disable" or "Prompt," which may enable security-sensitive operations that are inconsistent with the user's intended configuration.
References (4)
Core 4
Core References
Vendor Advisory vendor-advisory
x_refsource_ms
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-038
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/17820
US Government Resource third-party-advisory
x_refsource_cert
http://www.us-cert.gov/cas/techalerts/TA04-293A.html
Third Party Advisory, US Government Resource third-party-advisory
x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/630720
Scores
EPSS
0.0419
EPSS Percentile
90.0%
Details
Status
published
Products (3)
microsoft/ie
6.0 sp1 (2 CPE variants)
microsoft/internet_explorer
6.0
microsoft/windows_xp
(12 CPE variants)
Published
Dec 31, 2004
Tracked Since
Feb 18, 2026