>> Microsoft Windows Object Packager Dialogue Spoofing Vulnerability (MS06-065)
Title : Microsoft Windows Object Packager Dialogue Spoofing Vulnerability (MS06-065) VUPEN ID : VUPEN/ADV-2006-3984 CVE ID : CVE-2006-4692
Rated as : Low Risk
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2006-10-10
Technical Description
A vulnerability has been identified in Microsoft Windows, which could be exploited by attackers to bypass security restrictions and potentially execute arbitrary commands. This flaw is due to an error in the Object Packager (packager.exe) that does not validate the "Command Line" property, which could be exploited by malicious people to compromise a vulnerable system by convincing a user to open a specially crafted document, click on an embedded object within the file, and then accept a misleading dialogue indicating that the user is about access a different file type.