VulnerabilityModified
CVE-2004-0979
Internet Explorer on Windows XP does not properly modify the "Drag and Drop or copy and paste files" setting when the user sets it to "Disable" or "Prompt," which may enable security-sensitive operations that are inconsistent with the user's intended…
MEDIUM 4.6EPSS 4.19%
Does this matter?
Lower severity and a low EPSS score (4.19%). Track it; it rarely justifies an emergency change on its own.
Description
Internet Explorer on Windows XP does not properly modify the "Drag and Drop or copy and paste files" setting when the user sets it to "Disable" or "Prompt," which may enable security-sensitive operations that are inconsistent with the user's intended configuration.
- CVSS 2.0
- 4.6 MEDIUMAV:L/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 4.19% probability · 90th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/ie · microsoft/internet explorer · microsoft/windows xp
- Source
- cve@mitre.org
References
- http://www.kb.cert.org/vuls/id/630720Third Party Advisory, US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA04-293A.htmlUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-038
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17820
- http://www.kb.cert.org/vuls/id/630720Third Party Advisory, US Government Resource
- http://www.us-cert.gov/cas/techalerts/TA04-293A.htmlUS Government Resource
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-038
- https://exchange.xforce.ibmcloud.com/vulnerabilities/17820
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.