Windows Shell exposes 0day vulnerability

  

Microsoft released security bulletin KB2286198 on the weekend, pointing out that there is a serious 0day vulnerability in Windows Shell, which will lead to remote code execution. All current Windows versions are affected by this.

When a user uses a removable device (such as a USB device) and manually opens its root directory, the Windows Shell incorrectly resolves the path and may cause malicious code to execute. For systems that have autoplay disabled, users will need to manually browse the root directory of the removable disk folder, which could trigger the vulnerability.

Microsoft specifically reminds you that the Windows 7 system disables the autoplay feature of removable disks by default.

Windows versions affected by this vulnerability include: Windows XP SP3, Windows Server 2003 SP2, Windows Vista SP1/SP2, Windows Server 2008, Windows Server 2008 SP2, Windows 7, Windows Server 2008 R2.


Copyright © Windows knowledge All Rights Reserved