Microsoft Virtual Machine (VM) build 5.0.3805 and earlier allows remote attackers to determine a local users username via a Java applet that accesses the user.dir system property, aka User.dir Exposure Vulnerability.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Windows_2000 | Microsoft | * | * |
Windows_2000_terminal_services | Microsoft | * | * |
Windows_95 | Microsoft | * | * |
Windows_98 | Microsoft | * | * |
Windows_98se | Microsoft | * | * |
Windows_me | Microsoft | * | * |
Windows_nt | Microsoft | 4.0-sp1 (including) | 4.0-sp1 (including) |
Windows_nt | Microsoft | 4.0-sp2 (including) | 4.0-sp2 (including) |
Windows_nt | Microsoft | 4.0-sp3 (including) | 4.0-sp3 (including) |
Windows_nt | Microsoft | 4.0-sp4 (including) | 4.0-sp4 (including) |
Windows_nt | Microsoft | 4.0-sp5 (including) | 4.0-sp5 (including) |
Windows_nt | Microsoft | 4.0-sp6 (including) | 4.0-sp6 (including) |
Windows_nt | Microsoft | 4.0-sp6a (including) | 4.0-sp6a (including) |
Windows_xp | Microsoft | * | * |