Overview
Microsoft Management Console (MMC) is vulnerable to cross-site scripting, which may allow a remote attacker to execute arbitrary code on a vulnerable system.
Description
MMC MMC is an application that allows a user to perform administrative tasks. Through the use of various snap-ins, MMC can be used to configure Windows services, local users and groups, storage devices, and more. |
Impact
By convincing a user to view a specially crafted HTML document (e.g., a web page, an HTML email message, or an email attachment), an attacker could execute arbitrary code with the privileges of the user. |
Solution
Apply an update |
Workarounds
|
Vendor Information
CVSS Metrics
Group | Score | Vector |
---|---|---|
Base | ||
Temporal | ||
Environmental |
References
Acknowledgements
This vulnerability was reported by Microsoft, who in turn credit Yorick Koster of ITsec Security Services, H D Moore, and Tom Gilder.
This document was written by Will Dormann.
Other Information
CVE IDs: | CVE-2006-3643 |
Severity Metric: | 12.15 |
Date Public: | 2006-08-08 |
Date First Published: | 2006-08-08 |
Date Last Updated: | 2006-08-08 20:13 UTC |
Document Revision: | 4 |