Windows Essentials Improper URI Handling VulnerabilityID: oval:org.secpod.oval:def:10964 | Date: (C)2013-05-16 (M)2021-09-11 |
Class: VULNERABILITY | Family: windows |
The host is installed with Windows Essentials 2011 or 2012 and is prone to information disclosure vulnerability. A flaw is present in the application, which fails to properly handle URL parameters. Successful exploitation allows attackers to override Windows Writer proxy settings and overwrite files accessible to the user on the target system.
Platform: |
Microsoft Windows 7 |
Microsoft Windows 8 |
Microsoft Windows Server 2008 R2 |
Microsoft Windows Server 2012 |
Product: |
Microsoft Windows Essentials 2011 |
Microsoft Windows Essentials 2012 |