Описание
Cross-zone scripting vulnerability in the WMI Object Broker (WMIScriptUtils.WMIObjectBroker2) ActiveX control (WmiScriptUtils.dll) in Microsoft Visual Studio 2005 allows remote attackers to bypass Internet zone restrictions and execute arbitrary code by instantiating dangerous objects, aka "WMI Object Broker Vulnerability."
Cross-zone scripting vulnerability in the WMI Object Broker (WMIScriptUtils.WMIObjectBroker2) ActiveX control (WmiScriptUtils.dll) in Microsoft Visual Studio 2005 allows remote attackers to bypass Internet zone restrictions and execute arbitrary code by instantiating dangerous objects, aka "WMI Object Broker Vulnerability."
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2006-4704
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-073
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29915
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A288
- http://blogs.technet.com/msrc/archive/2006/11/01/microsoft-security-advisory-927709-posted.aspx
- http://research.eeye.com/html/alerts/zeroday/20061031.html
- http://secunia.com/advisories/22603
- http://securitytracker.com/id?1017142
- http://www.kb.cert.org/vuls/id/854856
- http://www.microsoft.com/technet/security/advisory/927709.mspx
- http://www.securityfocus.com/archive/1/454201/100/0/threaded
- http://www.securityfocus.com/archive/1/454969/100/200/threaded
- http://www.securityfocus.com/bid/20797
- http://www.securityfocus.com/bid/20843
- http://www.securityfocus.com/data/vulnerabilities/exploits/0day_ie.pdf
- http://www.us-cert.gov/cas/techalerts/TA06-346A.html
- http://www.vupen.com/english/advisories/2006/4282
- http://www.zerodayinitiative.com/advisories/ZDI-06-047.html
EPSS
CVE ID
Связанные уязвимости
Cross-zone scripting vulnerability in the WMI Object Broker (WMIScriptUtils.WMIObjectBroker2) ActiveX control (WmiScriptUtils.dll) in Microsoft Visual Studio 2005 allows remote attackers to bypass Internet zone restrictions and execute arbitrary code by instantiating dangerous objects, aka "WMI Object Broker Vulnerability."
EPSS