CVE-2000-0160

CVSS 2.0 Score 7.6 of 10 (high)

Details

Published Feb 21, 2000
Updated: Nov 20, 2024

Summary

CVE-2000-0160 is a vulnerability affecting the Microsoft Active Setup ActiveX component in Internet Explorer 4.x and 5.x. Malicious actors can exploit this issue to install software components without user consent, posing a significant risk to system security. The attacker, masquerading as Microsoft, can bypass the usual prompting mechanism, enabling unauthorized software installation. This vulnerability, if exploited, could lead to serious security consequences, including the potential for malware and unwanted software to be installed on a vulnerable system. Users are strongly advised to update their Internet Explorer versions to the latest patch to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Office Outlook
  • Microsoft Internet Explorer

Affected Vendors

  • Microsoft