This script is Copyright (C) 2007-2017 Tenable Network Security, Inc.
Arbitrary code can be executed on the remote host through the Win32
The remote host contains a version of the Win32 API that is vulnerable
to a security flaw that could allow a local user to gain elevated
privileges, and might allow a remote attacker to execute arbitrary code
on the host.
To exploit the flaw, an attacker would need to find a way to misuse the
Win32 API. One way of doing so would be to lure a user on the remote
host into visiting a specially crafted web page.
See also :
Microsoft has released a set of patches for Windows 2000, XP and
Risk factor :
High / CVSS Base Score : 9.3
CVSS Temporal Score : 8.1
Public Exploit Available : false