HTTP: Malicious OLE Object in Office Document

This signature detects attempts to exploit a known vulnerability against Windows Shell. Attackers can use this vulnerability to exploit a system if a user is logged on with administrative privileges. The attacker could take complete control of the affected system. However, user interaction is required to exploit this vulnerability.

Extended Description

Microsoft Windows is prone to a vulnerability that may allow remote attackers to execute code through the Windows Shell. The cause of the vulnerability is related to how the operating system handles unregistered file types. The specific issue is that files with an unknown extension may be opened with the application specified in the embedded CLSID. The victim of the attack would be required to open a malicious file, possibly hosted on a Web site or sent through email. Social engineering would generally be required to entice the victim into opening the file.

Affected Products

Microsoft windows_xp_media_center_edition

Short Name
HTTP:STC:OLE-SHELL
Severity
Major
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2005-0063 Document Malicious OLE Object Office bid:13132 in
Release Date
04/12/2005
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3375
False Positive
Unknown
Vendors

Microsoft

CVSS Score

7.5

Found a potential security threat?