Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs

Microsoft Windows Explorer Drag and Drop Remote Code Execution Vulnerability

Microsoft Windows is prone to a remote code-execution vulnerability. This issue affects the Windows Explorer component. This issue is caused by insecure handling of Drag and Drop events.

There is a public proof-of-concept that demonstrates that this vulnerability may be exploited to execute a malicious HTML application (HTA) without prompting the user for permission.







 

Privacy Statement
Copyright 2009, SecurityFocus