|
|||
Rule General Information |
---|
Release Date: | 2014-11-18 | |
Rule Name: | Microsoft Windows Vista Feed Headlines Gadget Code Execution Vulnerability -1 (CVE-2007-3033) | |
Severity: | ||
CVE ID: | ||
Rule Protection Details |
---|
Description: | Cross-site scripting (XSS) vulnerability in Windows Vista Feed Headlines Gadget (aka Sidebar RSS Feeds Gadget) in Windows Vista allows user-assisted remote attackers to execute arbitrary code via an RSS feed with crafted HTML attributes, which are not properly removed and are rendered in the local zone. | |
Impact: | An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software. | |
Affected OS: | Windows | |
Reference: | MicrosoftSecurityBulletin:ms07-048 SecurityFocusBID:25287 SecurityTrackerID:1018566 |
|
Solutions |
---|
Microsoft has released a patch MS07-048 to eliminate the vulnerability. The patch can be downloaded at http://www.microsoft.com/technet/security/bulletin/ms07-048.mspx |