Unrated severityNVD Advisory· Published Dec 31, 2004· Updated Jun 16, 2026
CVE-2004-2289
CVE-2004-2289
Description
Microsoft Windows XP Explorer allows local users to execute arbitrary code via a system folder with a Desktop.ini file containing a .ShellClassInfo specifier with a CLSID value that is associated with an executable file.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5cpe:2.3:o:microsoft:windows_xp:*:*:home:*:*:*:*:*+ 3 more
- cpe:2.3:o:microsoft:windows_xp:*:*:home:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_xp:*:gold:professional:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_xp:*:sp1:home:*:*:*:*:*
- (no CPE)
Patches
Vulnerability mechanics
References
7- archives.neohapsis.com/archives/bugtraq/2004-05/0168.htmlnvdExploitVendor Advisory
- www.freewebs.com/roozbeh_afrasiabi/xploit/execute.htmnvdExploit
- www.osvdb.org/6221nvdExploit
- secunia.com/advisories/11633nvdVendor Advisory
- www.securityfocus.com/bid/10363nvd
- docs.microsoft.com/en-us/security-updates/securitybulletins/2006/ms06-015nvd
- exchange.xforce.ibmcloud.com/vulnerabilities/16171nvd
News mentions
0No linked articles in our index yet.