| Definition Id: oval:org.mitre.oval:def:1004 |
Date: 2009-05-25 |
| Title: |
WinXP Management Vulnerability |
| Description: |
Windows XP allows local users to execute arbitrary programs by creating a task at an elevated privilege level through the eventtriggers.exe command-line tool or the Task Scheduler service, aka "Windows Management Vulnerability." |
| Version: |
4 |
Class: |
vulnerability |
| Status: |
ACCEPTED |
Reference(s): |
CVE-2003-0909
|
| Family: |
windows |
| Platform(s): |
Microsoft Windows XP |
Product(s): |
|
| Definition Synopsis: |
- A vulnerable version of evtgprov.dll exists on XP
- No service pack is installed, 32 bit Edition, and evtgprov.dll is less than 5.1.2600.136
- OR Affected evtgprov.dll versions on Windows XP SP1
- AND NOT the patch kb835732 is installed
- AND Windows XP (sp1 or earlier) is installed
|