
Find real vulnerabilities before they ship
The registry entry for the Windows Shell executable (Explorer.exe) in Windows NT and Windows 2000 uses a relative path name, which allows local users to execute arbitrary commands by inserting a Trojan Horse named Explorer.exe into the %Systemdrive% directory, aka the "Relative Shell Path" vulnerability.
| Base Score | 4.6 |
|---|---|
| Vector String | AV:L/AC:L/Au:N/C:P/I:P/A:P |
| Base Severity | Unknown |
| Version | 2.0 |
| Attack Vector (AV) |