CVE-2004-0726
The Windows Media Player control in Microsoft Windows 2000 allows remote attackers to execute arbitrary script in the local computer zone via an ASX filename that contains javascript, which is executed in the local context in a preview panel.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 11.4%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.
Description
The Windows Media Player control in Microsoft Windows 2000 allows remote attackers to execute arbitrary script in the local computer zone via an ASX filename that contains javascript, which is executed in the local context in a preview panel.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 11.42% probability · 96th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows 2000
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=108965512912175&w=2
- http://www.securityfocus.com/bid/10693Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16704
- http://marc.info/?l=bugtraq&m=108965512912175&w=2
- http://www.securityfocus.com/bid/10693Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16704
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.