积极预防 及时发现
快速响应 力保恢复
当访问.hlp文件时,Windows帮助文件允许本地用户通过编辑一个带有.CNT扩展名内容的元文件...
发布时间:2002-05-20 信息来源:管理员

CNCVE编号:CNCVE-19990975 CVE编号:CVE-1999-0975 安全级别:中 漏洞中文描述: 当访问.hlp文件时,Windows帮助文件允许本地用户通过编辑一个带有.CNT扩展名内容的元文件表,及修改topic action使其包括需要执行的命令,这样一来,本地用户就可以作为另一用户执行命令。 漏洞英文描述: The Windows help system can allow a local user to execute commands as another user by editing a table of contents metafile with a .CNT extension and modifying the topic action to include the commands to be executed when the .hlp file is accessed. 漏洞参考: 系统类型:其他 漏洞类型:其他