Microsoft Windows Vista does not properly enforce the NoDriveTypeAutoRun registry...
Vulnerability Description
Microsoft Windows Vista does not properly enforce the NoDriveTypeAutoRun registry value, which allows user-assisted remote attackers, and possibly physically proximate attackers, to execute arbitrary code by inserting a (1) CD-ROM device or (2) U3-enabled USB device containing a filesystem with an Autorun.inf file, and possibly other vectors related to (a) AutoRun and (b) AutoPlay actions.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2008-0951
Credits & Attribution
No credits recorded in the NVD database.
References
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41349
- http://www.securityfocus.com/bid/28360
- http://www.kb.cert.org/vuls/id/889747
- http://www.securitytracker.com/id?1020446
- https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-038
- http://www.vupen.com/english/advisories/2008/0954/references
- http://secunia.com/advisories/29458
More from microsoft
View All →Affected Vendor
microsoft
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.