This script is Copyright (C) 2010-2013 Tenable Network Security, Inc.
Arbitrary code can be executed on the remote host through the
Internet Connection Signup Wizard.
The remote Windows host contains a version of the Internet Connection
Signup Wizard that incorrectly restricts the path used for loading
If an attacker can trick a user on the affected system into opening a
specially crafted .ins or .isp file located in the same network
directory as a specially crafted dynamic link library (DLL) file, he
may be able to leverage this issue to execute arbitrary code subject
to the user's privileges.
See also :
Microsoft has released a set of patches for Windows XP, and 2003.
Risk factor :
High / CVSS Base Score : 9.3
CVSS Temporal Score : 7.7
Public Exploit Available : true