Описание
Microsoft Windows Vista does not properly enforce the NoDriveTypeAutoRun registry value, which allows user-assisted remote attackers, and possibly physically proximate attackers, to execute arbitrary code by inserting a (1) CD-ROM device or (2) U3-enabled USB device containing a filesystem with an Autorun.inf file, and possibly other vectors related to (a) AutoRun and (b) AutoPlay actions.
Microsoft Windows Vista does not properly enforce the NoDriveTypeAutoRun registry value, which allows user-assisted remote attackers, and possibly physically proximate attackers, to execute arbitrary code by inserting a (1) CD-ROM device or (2) U3-enabled USB device containing a filesystem with an Autorun.inf file, and possibly other vectors related to (a) AutoRun and (b) AutoPlay actions.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2008-0951
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-038
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41349
- http://secunia.com/advisories/29458
- http://www.kb.cert.org/vuls/id/889747
- http://www.securityfocus.com/bid/28360
- http://www.securitytracker.com/id?1020446
- http://www.vupen.com/english/advisories/2008/0954/references
Связанные уязвимости
Microsoft Windows Vista does not properly enforce the NoDriveTypeAutoRun registry value, which allows user-assisted remote attackers, and possibly physically proximate attackers, to execute arbitrary code by inserting a (1) CD-ROM device or (2) U3-enabled USB device containing a filesystem with an Autorun.inf file, and possibly other vectors related to (a) AutoRun and (b) AutoPlay actions.