MS03-008: Flaw in Windows Script Engine (814078)

This script is Copyright (C) 2003-2013 Tenable Network Security, Inc.


Synopsis :

Arbitrary code can be executed on the remote host through the web
client.

Description :

The remote host is vulnerable to a flaw in the Windows Script Engine,
that provides Windows with the ability to execute script code.

To exploit this flaw, an attacker would need to lure one user on this
host to visit a rogue website or to send a user an HTML email with a
malicious code in it.

See also :

http://technet.microsoft.com/en-us/security/bulletin/ms03-008

Solution :

Microsoft has released a set of patches for Windows NT, 2000 and XP.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 7.7
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: Windows : Microsoft Bulletins

Nessus Plugin ID: 11423 ()

Bugtraq ID: 7146

CVE ID: CVE-2003-0010