Unrated severityNVD Advisory· Published Mar 29, 2006· Updated Jun 16, 2026
CVE-2006-1476
CVE-2006-1476
Description
Windows Firewall in Microsoft Windows XP SP2 produces incorrect application block alerts when the application filename is ".exe" (with no characters before the "."), which might allow local user-assisted users to trick a user into unblocking a Trojan horse program, as demonstrated by a malicious ".exe" program in a folder named "Internet Explorer," which triggers a question about whether to unblock the "Internet Explorer" program.
Affected products
2cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*+ 1 more
- cpe:2.3:o:microsoft:windows_xp:*:sp2:tablet_pc:*:*:*:*:*
- (no CPE)range: =SP2
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.