Unquoted Windows search path vulnerability in Microsoft AntiSpyware might allow local users to execute code via a malicious c:\program.exe file, which is run by AntiSpywareMain.exe when it attempts to execute gsasDtServ.exe. NOTE: it is not clear whether this overlaps CVE-2005-2940.
Link | Tags |
---|---|
http://lists.grok.org.uk/pipermail/full-disclosure/2005-May/033909.html | exploit mailing list |
http://lists.grok.org.uk/pipermail/full-disclosure/2005-May/033910.html | mailing list |