CVE-2006-4465
Last modified
CVE-2006-4465 is a vulnerability of currently unknown severity. Microsoft Terminal Server, when running an application session with the "Start program at logon" and "Override settings from user profile and Client Connection Manager wizard" options, allows local users to execute arbitrary code by forcing an Explorer error. NOTE: a third-party researcher has stated that the options are "a convenience to users" and were not intended to restrict execution of arbitrary code. EPSS estimates a 9.19% chance of exploitation in the next 30 days.
Description
Microsoft Terminal Server, when running an application session with the "Start program at logon" and "Override settings from user profile and Client Connection Manager wizard" options, allows local users to execute arbitrary code by forcing an Explorer error. NOTE: a third-party researcher has stated that the options are "a convenience to users" and were not intended to restrict execution of arbitrary code
Metrics
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Terminal Server | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2006-4465?
How severe is CVE-2006-4465?
How do I fix CVE-2006-4465?
Are you affected by CVE-2006-4465?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
