>> Microsoft Windows Explorer Remote Code Execution (MS08-038)
Title : Microsoft Windows Explorer Remote Code Execution (MS08-038) VUPEN ID : VUPEN/ADV-2008-2020 CVE ID : CVE-2008-1435 CWE ID : CWE-20
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-07-08
Technical Description
A vulnerability has been identified in Microsoft Windows, which could be exploited by remote attackers to take complete control of an affected system. This issue is caused by an error in Windows Explorer that does not correctly parse search files when saving them, which could be exploited by attackers to execute arbitrary code by tricking a user into visiting a malicious web page, or opening a specially crafted file and saving the saved-search file.