CVE-2006-1475

Microsoft Windows XP SP2 - Local Privilege Escalation

Title source: llm
STIX 2.1

Description

Windows Firewall in Microsoft Windows XP SP2 does not produce application alerts when an application is executed using the NTFS Alternate Data Streams (ADS) filename:stream syntax, which might allow local users to launch a Trojan horse attack in which the victim does not obtain the alert that Windows Firewall would have produced for a non-ADS file.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/428970/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/25597
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/429111/100/0/threaded

Scores

EPSS 0.0168
EPSS Percentile 74.7%

Details

Status published
Products (1)
microsoft/windows_xp
Published Mar 29, 2006
Tracked Since Feb 18, 2026