Microsoft Baseline Security Analyzer (MBSA) 1.0 stores security scans in a known location C:\Documents and Settings\username\SecurityScans in plaintext, which could allow remote attackers to obtain sensitive information about the system via malicious active content such as ActiveX controls or Java.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/4594 | vdb entry exploit |
http://online.securityfocus.com/archive/1/269408 | mailing list |
https://exchange.xforce.ibmcloud.com/vulnerabilities/8947 | vdb entry |