MS05-013: Vulnerability in the DHTML Editing Component may allow code execution (891781)

This script is Copyright (C) 2005-2013 Tenable Network Security, Inc.


Synopsis :

Arbitrary code can be executed on the remote host through the web
client.

Description :

The remote host is running a version of Windows which contains a flaw
in the DHTML Editing Component ActiveX Control.

An attacker could exploit this flaw to execute arbitrary code on the
remote host.

To exploit this flaw, an attacker would need to construct a malicious
web page and lure a victim into visiting it.

See also :

http://technet.microsoft.com/en-us/security/bulletin/ms05-013

Solution :

Microsoft has released a set of patches for Windows 2000, XP and
2003.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 7.7
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true

Family: Windows : Microsoft Bulletins

Nessus Plugin ID: 16329 ()

Bugtraq ID: 11950

CVE ID: CVE-2004-1319