Карточка уязвимости
Характеристики уязвимости
Уровень опасности
Оценка CVSS
(AV:N/AC:H/Au:N/C:P/I:P/A:P)
Производитель ПО
Наименование ПО
Microsoft Windows
(1.1.4 x86 Windows 2000 Server SP4, 1.2.1 x86 Windows XP SP1, 1.2.2 x86 Windows XP SP2, 1.3.0 x86 Windows 2003 Server, 1.3.1 x86 Windows 2003 Server SP1, 2.2.0 x64 Windows XP, 2.3.0 x64 Windows 2003 Server, 3.3.0 i64 Windows 2003 Server , 3.3.1 i64 Windows 2003 Server SP1)
Microsoft Updates
(KB921398, KB928255)
Описание
В способе обработки событий перетаскивания проводником Windows существует уязвимость удаленного выполнения кода. Злоумышленник может использовать эту уязвимость, создав вредоносную веб-страницу, которая делает потенциально возможным сохранение злоумышленником файла в системе пользователя, посетившего вредоносную веб-страницу, или просмотревшего вредоносное сообщение электронной почты. Воспользовавшись этой уязвимостью, злоумышленник может захватить полный контроль над системой, Чтобы воспользоваться данной уязвимостью, необходимо участие пользователя.
Как исправить
Используйте рекомендации производителя:
http://www.microsoft.com/technet/security/Bulletin/MS06-045.mspx
http://www.microsoft.com/technet/security/Bulletin/MS06-045.mspx
Ссылки
FULLDISC (20060627 IE_ONE_MINOR_ONE_MAJOR): http://lists.grok.org.uk/pipermail/full-disclosure/2006-June/047398.html
http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20060627/3d930eda/PLEBO-2006.06.16-IE_ONE_MINOR_ONE_MAJOR.obj
BID (18682): http://www.securityfocus.com/bid/18682
FRSIRT (ADV-2006-2553): http://www.frsirt.com/english/advisories/2006/2553
CERT-VN (VU#655100): http://www.kb.cert.org/vuls/id/655100
SECTRACK (1016388): http://securitytracker.com/id?1016388
XF (ie-hta-fileshare-command-execution(27456)): http://xforce.iss.net/xforce/xfdb/27456
MS (MS06-045): http://www.microsoft.com/technet/security/Bulletin/MS06-045.mspx
CERT (TA06-220A): http://www.us-cert.gov/cas/techalerts/TA06-220A.html
BID (19389): http://www.securityfocus.com/bid/19389
OVAL (oval:org.mitre.oval:def:318): http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:318
http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20060627/3d930eda/PLEBO-2006.06.16-IE_ONE_MINOR_ONE_MAJOR.obj
BID (18682): http://www.securityfocus.com/bid/18682
FRSIRT (ADV-2006-2553): http://www.frsirt.com/english/advisories/2006/2553
CERT-VN (VU#655100): http://www.kb.cert.org/vuls/id/655100
SECTRACK (1016388): http://securitytracker.com/id?1016388
XF (ie-hta-fileshare-command-execution(27456)): http://xforce.iss.net/xforce/xfdb/27456
MS (MS06-045): http://www.microsoft.com/technet/security/Bulletin/MS06-045.mspx
CERT (TA06-220A): http://www.us-cert.gov/cas/techalerts/TA06-220A.html
BID (19389): http://www.securityfocus.com/bid/19389
OVAL (oval:org.mitre.oval:def:318): http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:318