This script is Copyright (C) 2006-2013 Tenable Network Security, Inc.
Synopsis :
Arbitrary code can be executed on the remote host through the web
client.
Description :
The remote host is missing IE Cumulative Security Update 918899.
The remote version of IE is vulnerable to several flaws that could
allow an attacker to execute arbitrary code on the remote host.
Note that Microsoft has re-released this hotfix since the initial
version contained a buffer overflow.
See also :
http://support.microsoft.com/kb/923762/
Solution :
Microsoft has released a set of patches for Windows 2000, XP and
2003 :
http://technet.microsoft.com/en-us/security/bulletin/ms06-042
Risk factor :
High / CVSS Base Score : 7.5
(CVSS2#AV:N/AC:L/Au:N/C:P/I:P/A:P)
CVSS Temporal Score : 6.2
(CVSS2#E:F/RL:OF/RC:C)
Public Exploit Available : true
Family: Windows : Microsoft Bulletins
Nessus Plugin ID: 22184 ()
Bugtraq ID: 11826
18277
18682
19228
19312
19316
19339
19340
19400
19987
CVE ID: CVE-2004-1166
CVE-2006-3280
CVE-2006-3450
CVE-2006-3451
CVE-2006-3637
CVE-2006-3638
CVE-2006-3639
CVE-2006-3640
CVE-2006-3873
CVE-2006-7066