Heap
23-01-09, 02:42
Microsoft Windows does not properly enforce the Autorun and NoDriveTypeAutoRun registry values, which allows physically proximate attackers to execute arbitrary code by (1) inserting CD-ROM media, (2) inserting DVD media, (3) connecting a USB device, and (4) connecting a Firewire device; (5) allows user-assisted remote attackers to execute arbitrary code by mapping a network drive; and allows user-assisted attackers to execute arbitrary code by clicking on (6) an icon under My Computer\Device...
More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-0243)
More... (http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2009-0243)