9.3
CVSSv2

CVE-2007-1658

Published: 24/03/2007 Updated: 16/10/2018
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Windows Mail in Microsoft Windows Vista might allow user-assisted remote malicious users to execute certain programs via a link to a (1) local file or (2) UNC share pathname in which there is a directory with the same base name as an executable program at the same level, as demonstrated using C:/windows/system32/winrm (winrm.cmd) and migwiz (migwiz.exe).

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft windows vista

Exploits

source: wwwsecurityfocuscom/bid/23103/info Microsoft Windows Vista Windows Mail is prone to a local file-execution vulnerability due to a design error An attackers may exploit this issue to execute local files The attacker must entice a victim into opening a maliciously crafted link using the affected application The vendor reports t ...