CVE-2006-1476

Windows Firewall - XP SP2 - Info Disclosure

Title source: llm
STIX 2.1

Description

Windows Firewall in Microsoft Windows XP SP2 produces incorrect application block alerts when the application filename is ".exe" (with no characters before the "."), which might allow local user-assisted users to trick a user into unblocking a Trojan horse program, as demonstrated by a malicious ".exe" program in a folder named "Internet Explorer," which triggers a question about whether to unblock the "Internet Explorer" program.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/428970/100/0/threaded
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/25598
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/429111/100/0/threaded

Scores

EPSS 0.0391
EPSS Percentile 89.3%

Details

Status published
Products (1)
microsoft/windows_xp
Published Mar 29, 2006
Tracked Since Feb 18, 2026