This script is Copyright (C) 2007-2014 Tenable Network Security, Inc.
Arbitrary code can be executed on the remote host through the web
The remote host is running a version of Windows containing a bug in the
CSRSS error message handling routine that could allow an attacker to
execute arbitrary code on the remote host by luring a user on the remote
host into visiting a rogue website.
Additionally, the system is prone to the following types of attack :
- Local Privilege Elevation
- Denial of Service (Local)
See also :
Microsoft has released a set of patches for Windows 2000, XP, 2003 and
Risk factor :
High / CVSS Base Score : 9.3
CVSS Temporal Score : 7.3
Public Exploit Available : true