Description
Buffer overflow in Windows Explorer (explorer.exe) on Windows XP and 2003 allows user-assisted attackers to cause a denial of service (repeated crash) and possibly execute arbitrary code via a .url file with an InternetShortcut tag containing a long URL and a large number of "file:" specifiers.
References (5)
Core 5
Core References
Third Party Advisory third-party-advisory
x_refsource_sreason
http://securityreason.com/securityalert/1186
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/439660/100/200/threaded
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/27567
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/439153/100/0/threaded
Exploit vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/18838
Scores
EPSS
0.0693
EPSS Percentile
93.5%
Details
Status
published
Products (16)
microsoft/windows_2003_server
3.1.0.3270
microsoft/windows_2003_server
64-bit
microsoft/windows_2003_server
datacenter_64-bit sp1 (2 CPE variants)
microsoft/windows_2003_server
datacenter_edition (3 CPE variants)
microsoft/windows_2003_server
datacenter_edition_64-bit (3 CPE variants)
microsoft/windows_2003_server
enterprise (3 CPE variants)
microsoft/windows_2003_server
enterprise_64-bit (3 CPE variants)
microsoft/windows_2003_server
enterprise_edition sp1 (2 CPE variants)
microsoft/windows_2003_server
enterprise_edition_64-bit (3 CPE variants)
microsoft/windows_2003_server
itanium
... and 6 more
Published
Jul 06, 2006
Tracked Since
Feb 18, 2026