-
MS10-052 (2115168)
Microsoft Security Bulletin MS10-052
[B]Vulnerability in Microsoft MPEG Layer-3 Codecs Could Allow Remote Code Execution[/B] (2115168)
[url]http://www.microsoft.com/technet/security/Bulletin/MS10-052.mspx[/url]
[B]Âûïîëíåíèå ïðîèçâîëüíîãî êîäà â Microsoft MPEG Layer-3 àóäèî äåêîäåðå[/B]
[url]http://www.securitylab.ru/vulnerability/396553.php[/url]
[B]Rating: [color=#CC0000]Critical[/color][/B]
[B]Îïèñàíèå:[/B]
Óÿçâèìîñòü ïîçâîëÿåò óäàëåííîìó ïîëüçîâàòåëþ ñêîìïðîìåòèðîâàòü öåëåâóþ ñèñòåìó.
Óÿçâèìîñòü ñóùåñòâóåò èç-çà îøèáêè â Microsoft DirectShow MP3 ôèëüòðå (l3codecx.ax) ïðè îáðàáîòêå MPEG Layer-3 àóäèî ïîòîêîâ. Óäàëåííûé ïîëüçîâàòåëü ìîæåò ñ ïîìîùüþ ñïåöèàëüíî ñôîðìèðîâàííîãî àóäèî ôàéëà âûçâàòü ïåðåïîëíåíèå äèíàìè÷åñêîé ïàìÿòè è âûïîëíèòü ïðîèçâîëüíûé êîä íà öåëåâîé ñèñòåìå.
[B][color=#CC0000]Affected Software[/color]:[/B]
• Windows XP Service Pack 3
• Windows XP Professional x64 Edition Service Pack 2
• Windows Server 2003 Service Pack 2
• Windows Server 2003 x64 Edition Service Pack 2
[B][color=#006600]Non-Affected Software[/color]:[/B]
• Windows Server 2003 with SP2 for Itanium-based Systems
• Windows Vista Service Pack 1, and Windows Vista Service Pack 2
• Windows Vista x64 Edition Service Pack 1, and Windows Vista x64 Edition Service Pack 2
• Windows Server 2008 for 32-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2
• Windows Server 2008 for x64-based Systems and Windows Server 2008 for x64-based Systems Service Pack 2
• Windows Server 2008 for Itanium-based Systems and Windows Server 2008 for Itanium-based Systems Service Pack 2
• Windows 7 for 32-bit Systems
• Windows 7 for x64-based Systems
• Windows Server 2008 R2 for x64-based Systems
• Windows Server 2008 R2 for Itanium-based Systems
-
MS10-053 (2183461)
Microsoft Security Bulletin MS10-053
[B]Cumulative Security Update for Internet Explorer[/B] (2183461)
[url]http://www.microsoft.com/technet/security/bulletin/ms10-053.mspx[/url]
[B]Ìíîæåñòâåííûå óÿçâèìîñòè â Microsoft Internet Explorer[/B]
[url]http://www.securitylab.ru/vulnerability/396555.php[/url]
[B]Âûïîëíåíèå ïðîèçâîëüíîãî êîäà â Internet Explorer 6[/B]
[url]http://www.securitylab.ru/vulnerability/396556.php[/url]
[B]Âûïîëíåíèå ïðîèçâîëüíîãî êîäà â Internet Explorer 8[/B]
[url]http://www.securitylab.ru/vulnerability/396557.php[/url]
[B]Rating: [color=#CC0000]Critical[/color][/B]
Îïèñàíèå:
Îáíàðóæåííûå óÿçâèìîñòè ïîçâîëÿþò óäàëåííîìó ïîëüçîâàòåëþ ïîëó÷èòü äîñòóï ê âàæíûì äàííûì è ñêîìïðîìåòèðîâàòü öåëåâóþ ñèñòåìó.
1. Óÿçâèìîñòü ñóùåñòâóåò èç-çà òîãî, ÷òî ïðèëîæåíèå íåêîððåêòíî èíòåðïðåòèðóåò ïðîèñõîæäåíèå ñöåíàðèåâ, è ïîçâîëÿåò ñöåíàðèþ çàïóñòèòüñÿ â êîíòåêñòå äðóãîãî äîìåíà èëè äðóãîé çîíû Internet Explorer. Óäàëåííûé ïîëüçîâàòåëü ìîæåò ïîëó÷èòü äîñòóï ê ïîòåíöèàëüíî âàæíûì äàííûì ïîëüçîâàòåëÿ. Äëÿ óñïåøíîé ýêñïëóàòàöèè óÿçâèìîñòè çëîóìûøëåííèê äîëæåí îáìàíîì çàñòàâèòü ïîëüçîâàòåëÿ ïðîèçâåñòè íåêîòîðûå ìàíèïóëÿöèè ñ ìûøüþ â îêíå áðàóçåðà.
2. Óÿçâèìîñòü ñóùåñòâóåò èç-çà îøèáêè ïðè äîñòóïå ê îáúåêòó, êîòîðûé áûë íåêîððåêòíî èíèöèàëèçèðîâàí èëè óäàëåí. Óäàëåííûé ïîëüçîâàòåëü ìîæåò ñ ïîìîùüþ ñïåöèàëüíî ñôîðìèðîâàííîãî Web ñàéòà âûçâàòü ïîâðåæäåíèå ïàìÿòè è âûïîëíèòü ïðîèçâîëüíûé êîä íà öåëåâîé ñèñòåìå.
3. Óÿçâèìîñòü ñóùåñòâóåò èç-çà îøèáêè ñîñòîÿíèÿ îïåðàöèè ïðè îáðàùåíèè ê îáúåêòàì. Óäàëåííûé ïîëüçîâàòåëü ìîæåò ñ ïîìîùüþ ñïåöèàëüíî ñôîðìèðîâàííîãî Web ñàéòà âûçâàòü ïîâðåæäåíèå ïàìÿòè è âûïîëíèòü ïðîèçâîëüíûé êîä íà öåëåâîé ñèñòåìå.
4. Óÿçâèìîñòü ñóùåñòâóåò èç-çà îøèáêè ïðè äîñòóïå ê îáúåêòó, êîòîðûé áûë íåêîððåêòíî èíèöèàëèçèðîâàí èëè óäàëåí. Óäàëåííûé ïîëüçîâàòåëü ìîæåò ñ ïîìîùüþ ñïåöèàëüíî ñôîðìèðîâàííîãî Web ñàéòà âûçâàòü ïîâðåæäåíèå ïàìÿòè è âûïîëíèòü ïðîèçâîëüíûé êîä íà öåëåâîé ñèñòåìå.
[B][color=#CC0000]Affected Software[/color]:[/B]
• Microsoft Internet Explorer 6[indent]• Microsoft Windows XP Service Pack 2 and Microsoft Windows XP Service Pack 3
• Microsoft Windows XP Professional x64 Edition and Microsoft Windows XP Professional x64 Edition Service Pack 2
• Microsoft Windows Server 2003 Service Pack 1 and Microsoft Windows Server 2003 Service Pack 2
• Microsoft Windows Server 2003 with SP1 for Itanium-based Systems and Microsoft Windows Server 2003 with SP2 for Itanium-based Systems
• Microsoft Windows Server 2003 x64 Edition Service Pack 1 and Microsoft Windows Server 2003 x64 Edition Service Pack 2[/indent]
• Windows Internet Explorer 7[indent]• Microsoft Windows XP Service Pack 2 and Microsoft Windows XP Service Pack 3
• Microsoft Windows XP Professional x64 Edition and Microsoft Windows XP Professional x64 Edition Service Pack 2
• Microsoft Windows Server 2003 Service Pack 1 and Microsoft Windows Server 2003 Service Pack 2
• Microsoft Windows Server 2003 with SP1 for Itanium-based Systems and Microsoft Windows Server 2003 with SP2 for Itanium-based Systems
• Microsoft Windows Server 2003 x64 Edition Service Pack 1 and Microsoft Windows Server 2003 x64 Edition Service Pack 2
• Windows Vista Service Pack 2
• Windows Vista x64 Edition Service Pack 2
• Windows Server 2008 for 32-bit Systems
• Windows Server 2008 for x64-based Systems
• Windows Server 2008 for Itanium-based Systems[/indent]
• Windows Internet Explorer 8[indent]• Microsoft Windows XP Service Pack 2 and Microsoft Windows XP Service Pack 3
• Microsoft Windows XP Professional x64 Edition and Microsoft Windows XP Professional x64 Edition Service Pack 2
• Microsoft Windows Server 2003 Service Pack 1 and Microsoft Windows Server 2003 Service Pack 2
• Microsoft Windows Server 2003 x64 Edition Service Pack 1 and Microsoft Windows Server 2003 x64 Edition Service Pack 2
• Windows Vista Service Pack 2
• Windows Vista x64 Edition Service Pack 2
• Windows Server 2008 for 32-bit Systems
• Windows Server 2008 for x64-based Systems
• Windows 7 for 32-bit Systems
• Windows 7 for x64-based Systems
• Windows Server 2008 R2 for x64-based Systems
• Windows Server 2008 R2 for Itanium-based Systems[/indent]
-
MS10-054 (982214)
Microsoft Security Bulletin MS10-054
[B]Vulnerabilities in SMB Server Could Allow Remote Code Execution[/B] (982214)
[url]http://www.microsoft.com/technet/security/Bulletin/MS10-054.mspx[/url]
[B]Âûïîëíåíèå ïðîèçâîëüíîãî êîäà â Microsoft Windows SMB[/B]
[url]http://www.securitylab.ru/vulnerability/396559.php[/url]
[B]Îòêàç â îáñëóæèâàíèè â Microsoft Windows SMB[/B]
[url]http://www.securitylab.ru/vulnerability/396560.php[/url]
[B]Rating: [color=#CC0000]Critical[/color][/B]
[B]Îïèñàíèå:[/B]
Îáíàðóæåííûå óÿçâèìîñòè ïîçâîëÿþò óäàëåííîìó ïîëüçîâàòåëþ âûçâàòü îòêàç â îáñëóæèâàíèè è ñêîìïðîìåòèðîâàòü öåëåâóþ ñèñòåìó.
1. Óÿçâèìîñòü ñóùåñòâóåò èç-çà íåäîñòàòî÷íîé îáðàáîòêè ïîëåé â Microsoft Server Message Block (SMB) ïàêåòàõ. Óäàëåííûé íåàóòåíòèôèöèðîâàííûé ïîëüçîâàòåëü ìîæåò ñ ïîìîùüþ ñïåöèàëüíî ñôîðìèðîâàííîãî SMB ïàêåòà âûçâàòü ïåðåïîëíåíèå SMB ïóëà è âûïîëíèòü ïðîèçâîëüíûé êîä íà öåëåâîé ñèñòåìå.
2. Óÿçâèìîñòü ñóùåñòâóåò èç-çà îøèáêè ïðè îáðàáîòêå âíóòðåííèõ ïåðåìåííûõ â SMB ïàêåòàõ. Óäàëåííûé ïîëüçîâàòåëü ìîæåò ñ ïîìîùüþ ñïåöèàëüíî ñôîðìèðîâàííîãî SMB ïàêåòà àâàðèéíî çàâåðøèòü ðàáîòó ñèñòåìû.
3. Óÿçâèìîñòü ñóùåñòâóåò èç-çà îøèáêè ïðè îáðàáîòêå ñëîæíûõ çàïðîñîâ. Óäàëåííûé ïîëüçîâàòåëü ìîæåò ñ ïîìîùüþ ñïåöèàëüíî ñôîðìèðîâàííîãî SMB ïàêåòà âûçâàòü îòêàç â îáñëóæèâàíèè ñèñòåìû.
[B][color=#CC0000]Affected Software[/color]:[/B]
• Windows XP Service Pack 3
• Windows XP Professional x64 Edition Service Pack 2
• Windows Server 2003 Service Pack 2
• Windows Server 2003 x64 Edition Service Pack 2
• Windows Server 2003 with SP2 for Itanium-based Systems
• Windows Vista Service Pack 1 and Windows Vista Service Pack 2
• Windows Vista x64 Edition Service Pack 1 and Windows Vista x64 Edition Service Pack 2
• Windows Server 2008 for 32-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2
• Windows Server 2008 for x64-based Systems and Windows Server 2008 for x64-based Systems Service Pack 2
• Windows Server 2008 for Itanium-based Systems and Windows Server 2008 for Itanium-based Systems Service Pack 2
• Windows 7 for 32-bit Systems
• Windows 7 for x64-based Systems
• Windows Server 2008 R2 for x64-based Systems
• Windows Server 2008 R2 for Itanium-based Systems
-
MS10-055 (982665)
Microsoft Security Bulletin MS10-055
[B]Vulnerability in Cinepak Codec Could Allow Remote Code Execution [/B](982665)
[url]http://www.microsoft.com/technet/security/Bulletin/MS10-055.mspx[/url]
[B]Âûïîëíåíèå ïðîèçâîëüíîãî êîäà â Microsoft Windows Cinepak êîäåêå[/B]
[url]http://www.securitylab.ru/vulnerability/396563.php[/url]
[B]Rating: [color=#CC0000]Critical[/color][/B]
[B]Îïèñàíèå:[/B]
Óÿçâèìîñòü ïîçâîëÿåò óäàëåííîìó ïîëüçîâàòåëþ ñêîìïðîìåòèðîâàòü öåëåâóþ ñèñòåìó.
Óÿçâèìîñòü ñóùåñòâóåò èç-çà îøèáêè ïðîâåðêè ãðàíèö äàííûõ ïðè îáðàáîòêå RGB ïàëèòðû â ôóíêöèè CVDecompress() â êîäåêå Cinepak (iccvid.dll). Óäàëåííûé ïîëüçîâàòåëü ìîæåò ñ ïîìîùüþ ñïåöèàëüíî ñôîðìèðîâàííîãî ñæàòîãî VIDC ïîòîêà â .avi ôàéëå âûïîëíèòü ïðîèçâîëüíûé êîä íà öåëåâîé ñèñòåìå.
[B][color=#CC0000]Affected Software[/color]:[/B]
• Windows XP Service Pack 3
• Windows XP Professional x64 Edition Service Pack 2
• Windows Vista Service Pack 1, and Windows Vista Service Pack 2
• Windows Vista x64 Edition Service Pack 1, and Windows Vista x64
• Windows 7 for 32-bit Systems
• Windows 7 for x64-based Systems
[B][color=#006600]Non-Affected Software[/color]:[/B]
• Windows Server 2003 Service Pack 2
• Windows Server 2003 x64 Edition Service Pack 2
• Windows Server 2003 with SP2 for Itanium-based Systems Edition Service Pack 2
• Windows Server 2008 for 32-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2
• Windows Server 2008 for x64-based Systems and Windows Server 2008 for x64-based Systems Service Pack 2
• Windows Server 2008 for Itanium-based Systems and Windows Server 2008 for Itanium-based Systems Service Pack 2
• Windows Server 2008 R2 for x64-based Systems
• Windows Server 2008 R2 for Itanium-based Systems
-
MS10-056 (2269638)
Microsoft Security Bulletin MS10-056
[B]Vulnerabilities in Microsoft Office Word Could Allow Remote Code Execution [/B](2269638)
[url]http://www.microsoft.com/technet/security/bulletin/ms10-056.mspx[/url]
[B]
Âûïîëíåíèå ïðîèçâîëüíîãî êîäà â Microsoft Office Excel[/B]
[url]http://www.securitylab.ru/vulnerability/396577.php[/url]
[B]Rating: [color=#CC0000]Critical[/color][/B]
[B]Îïèñàíèå:[/B]
Óÿçâèìîñòü ïîçâîëÿåò óäàëåííîìó ïîëüçîâàòåëþ âûïîëíèòü ïðîèçâîëüíûé êîä íà öåëåâîé ñèñòåìå.
Óÿçâèìîñòü ñóùåñòâóåò èç-çà íåäîñòàòî÷íîé îáðàáîòêè PivotTable Cache Data çàïèñåé â .xls ôàéëàõ. Óäàëåííûé ïîëüçîâàòåëü ìîæåò ñ ïîìîùüþ ñïåöèàëüíî ñôîðìèðîâàííîãî .xls ôàéëà âûçâàòü ïåðåïîëíåíèå ñòåêà è âûïîëíèòü ïðîèçâîëüíûé êîä íà öåëåâîé ñèñòåìå.
[B][color=#CC0000]Affected Software[/color]:[/B]
• Microsoft Office XP Service Pack 3[indent]• Microsoft Office Word 2002 Service Pack 3[/indent]• Microsoft Office 2003 Service Pack 3[indent]• Microsoft Office Word 2003 Service Pack 3[/indent]• 2007 Microsoft Office System Service Pack 2[indent]• Microsoft Office Word 2007 Service Pack 2[/indent]
• Microsoft Office 2004 for Mac
• Microsoft Office 2008 for Mac
• Open XML File Format Converter for Mac
• Microsoft Office Word Viewer
• Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 2
• Microsoft Works 9
[B][color=#006600]Non-Affected Software[/color]:[/B]
• Microsoft Office Word 2010 (32-bit editions)
• Microsoft Office Word 2010 (64-bit editions)
-
MS10-057 (2269707)
Microsoft Security Bulletin MS10-057
[B]Vulnerability in Microsoft Office Excel Could Allow Remote Code Execution [/B](2269707)
[url]http://www.microsoft.com/technet/security/bulletin/ms10-057.mspx[/url]
[B]Ìíîæåñòâåííûå óÿçâèìîñòè â Microsoft Word[/B]
[url]http://www.securitylab.ru/vulnerability/396572.php[/url]
[B]Óÿçâèìîñòü ïðè îáðàáîòêå ñâÿçàííûõ HTML îáúåêòîâ â Microsoft Office Word[/B]
[url]http://www.securitylab.ru/vulnerability/396573.php[/url]
[B]Âûïîëíåíèå ïðîèçâîëüíîãî êîäà â Microsoft Works[/B]
[url]http://www.securitylab.ru/vulnerability/396574.php[/url]
[B]Rating: [color=#FF6600]Important[/color][/B]
[B]Îïèñàíèå:[/B]
Îáíàðóæåííûå óÿçâèìîñòè ïîçâîëÿþò óäàëåííîìó ïîëüçîâàòåëþ ñêîìïðîìåòèðîâàòü öåëåâóþ ñèñòåìó, âûïîëíèòü ïðîèçâîëüíûé êîä íà öåëåâîé ñèñòåìå.
1. Óÿçâèìîñòü ñóùåñòâóåò èç-çà îøèáêè ïðè îáðàáîòêå çàïèñåé âíóòðè Word ôàéëà. Óäàëåííûé ïîëüçîâàòåëü ìîæåò ñ ïîìîùüþ ñïåöèàëüíî ñôîðìèðîâàííîãî äîêóìåíòà Word âûçâàòü ïîâðåæäåíèå ïàìÿòè è âûïîëíèòü ïðîèçâîëüíûé êîä íà öåëåâîé ñèñòåìå.
2. Óÿçâèìîñòü ñóùåñòâóåò èç-çà îøèáêè ïðè îáðàáîòêå rich text äàííûõ. Óäàëåííûé ïîëüçîâàòåëü ìîæåò ñ ïîìîùüþ ñïåöèàëüíî ñôîðìèðîâàííîãî RTF ôàéëà âûçâàòü ïîâðåæäåíèå ïàìÿòè è âûïîëíèòü ïðîèçâîëüíûé êîä íà öåëåâîé ñèñòåìå.
3. Óÿçâèìîñòü ñóùåñòâóåò èç-çà îøèáêè ïðè îáðàáîòêå íåêîòîðûõ îáúåêòîâ â RTF ôàéëàõ. Óäàëåííûé ïîëüçîâàòåëü ìîæåò ñ ïîìîùüþ ñïåöèàëüíî ñôîðìèðîâàííîãî RTF ôàéëà âûçâàòü ïåðåïîëíåíèå äèíàìè÷åñêîé ïàìÿòè è âûïîëíèòü ïðîèçâîëüíûé êîä íà öåëåâîé ñèñòåìå.
4. Óÿçâèìîñòü ñóùåñòâóåò èç-çà îøèáêè ïðè îáðàáîòêå ñâÿçàííûõ HTML îáúåêòîâ. Óäàëåííûé ïîëüçîâàòåëü ìîæåò ñ ïîìîùüþ ñïåöèàëüíî ñôîðìèðîâàííîãî Word ôàéëà âûçâàòü ïîâðåæäåíèå ïàìÿòè è âûïîëíèòü ïðîèçâîëüíûé êîä íà öåëåâîé ñèñòåìå.
[B][color=#CC0000]Affected Software[/color]:[/B]
• Microsoft Office XP Service Pack 3[indent]• Microsoft Office Excel 2002 Service Pack 3[/indent]• Microsoft Office 2003 Service Pack 3[indent]• Microsoft Office Excel 2003 Service Pack 3[/indent]• Microsoft Office 2004 for Mac
• Microsoft Office 2008 for Mac
• Open XML File Format Converter for Mac
[B][color=#006600]Non-Affected Software[/color]:[/B]
• Microsoft Office Excel 2007 Service Pack 2
• Microsoft Office Excel 2010 (32-bit editions)
• Microsoft Office Excel 2010 (64-bit editions)
• Microsoft Office Excel Viewer Service Pack 2
• Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats Service Pack 2
• Microsoft Works 9
-
MS10-058 (978886)
Microsoft Security Bulletin MS10-058
[B]Vulnerabilities in TCP/IP Could Allow Elevation of Privilege[/B] (978886)
[url]http://www.microsoft.com/technet/security/bulletin/MS10-058.mspx[/url]
[B]
Ìíîæåñòâåííûå óÿçâèìîñòè â ðåàëèçàöèè TCP/IP â Microsoft Windows[/B]
[url]http://www.securitylab.ru/vulnerability/396579.php[/url]
[B]Rating: [color=#FF6600]Important[/color][/B]
[B]Îïèñàíèå:[/B]
Îáíàðóæåííûå óÿçâèìîñòè ïîçâîëÿþò çëîóìûøëåííèêó âûçâàòü îòêàç â îáñëóæèâàíèè è ïîâûñèòü ñâîè ïðèâèëåãèè íà ñèñòåìå.
1. Óÿçâèìîñòü ñóùåñòâóåò èç-çà îøèáêè ïðè îáðàáîòêå IPv6 ïàêåòîâ. Óäàëåííûé ïîëüçîâàòåëü ìîæåò ñ ïîìîùüþ íåáîëüøîãî êîëè÷åñòâà IPv6 ïàêåòîâ, ñîäåðæàùèõ íåêîððåêòíûé çàãîëîâîê ðàñøèðåíèÿ âûçâàòü îòêàç â îáñëóæèâàíèè ñèñòåìû.
2. Öåëî÷èñëåííîå ïåðåïîëíåíèå ñóùåñòâóåò èç-çà íåêîððåêòíîé îáðàáîòêè äàííûõ, êîïèðóåìûõ èç ïðîñòðàíñòâà ïîëüçîâàòåëÿ. Ëîêàëüíûé ïîëüçîâàòåëü ìîæåò âûçâàòü ïåðåïîëíåíèå áóôåðà è âûïîëíèòü ïðîèçâîëüíûé êîä íà öåëåâîé ñèñòåìå ñ ïîâûøåííûìè ïðèâèëåãèÿìè.
[B][color=#CC0000]Affected Software[/color]:[/B]
• Windows Vista Service Pack 1, and Windows Vista Service Pack 2
• Windows Vista x64 Edition Service Pack 1, and Windows Vista x64 Edition Service Pack 2
• Windows Server 2008 for 32-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2
• Windows Server 2008 for x64-based Systems and Windows Server 2008 for x64-based Systems Service Pack 2
• Windows Server 2008 for Itanium-based Systems and Windows Server 2008 for Itanium-based Systems Service Pack 2
• Windows 7 for 32-bit Systems
• Windows 7 for x64-based Systems
• Windows Server 2008 R2 for x64-based Systems
• Windows Server 2008 R2 for Itanium-based Systems
[B][color=#006600]Non-Affected Software[/color]:[/B]
• Windows XP Service Pack 3
• Windows XP Professional x64 Edition Service Pack 2
• Windows Server 2003 Service Pack 2
• Windows Server 2003 x64 Edition Service Pack 2
• Windows Server 2003 with SP2 for Itanium-based Systems
-
MS10-059 (982799)
Microsoft Security Bulletin MS10-059
[B]Vulnerabilities in the Tracing Feature for Services Could Allow Elevation of Privilege[/B] (982799)
[url]http://www.microsoft.com/technet/security/Bulletin/MS10-059.mspx[/url]
[B]
Ïîâûøåíèå ïðèâèëåãèé â ôóíêöèîíàëå òðàññèðîâêè â Microsoft Windows[/B]
[url]http://www.securitylab.ru/vulnerability/396581.php[/url]
[B]Rating: [color=#FF6600]Important[/color][/B]
[B]Îïèñàíèå:[/B]
Îáíàðóæåííûå óÿçâèìîñòè ïîçâîëÿþò ëîêàëüíîìó ïîëüçîâàòåëþ ïîâûñèòü ñâîè ïðèâèëåãèè íà ñèñòåìå.
1. Óÿçâèìîñòü ñóùåñòâóåò èç-çà òîãî, ÷òî Windows óñòàíàâëèâàåò íåêîððåêòíûå ñïèñêè êîíòðîëÿ äîñòóïà ê êëþ÷àì ðååñòðà äëÿ Tracing Feature for Services. Ëîêàëüíûé ïîëüçîâàòåëü ìîæåò èçìåíèòü êëþ÷è â âåòêå ðååñòðà HKLM\Software\Microsoft\Tracing è ïîâûñèòü ñâîè ïðèâèëåãèè íà ñèñòåìå.
2. Óÿçâèìîñòü ñóùåñòâóåò èç-çà îøèáêè ïðè îáðàáîòêå ñëèøêîì äëèííûõ ñòðîê, ïîëó÷åííûõ èç ðååñòðà, â Tracing Feature for Services. Ëîêàëüíûé ïîëüçîâàòåëü ìîæåò âûïîëíèòü ïðîèçâîëüíûé êîä íà öåëåâîé ñèñòåìå ñ ïîâûøåííûìè ïðèâèëåãèÿìè.
[B][color=#CC0000]Affected Software[/color]:[/B]
• Windows Vista Service Pack 1, and Windows Vista Service Pack 2
• Windows Vista x64 Edition Service Pack 1, and Windows Vista x64 Edition Service Pack 2
• Windows Server 2008 for 32-bit Systems and Windows Server 2008 for 32-bit Systems Service Pack 2
• Windows Server 2008 for x64-based Systems and Windows Server 2008 for x64-based Systems Service Pack 2
• Windows Server 2008 for Itanium-based Systems and Windows Server 2008 for Itanium-based Systems Service Pack 2
• Windows 7 for 32-bit Systems
• Windows 7 for x64-based Systems
• Windows Server 2008 R2 for x64-based Systems
• Windows Server 2008 R2 for Itanium-based Systems
[B][color=#006600]Non-Affected Software[/color]:[/B]
• Windows XP Service Pack 3
• Windows XP Professional x64 Edition Service Pack 2
• Windows Server 2003 Service Pack 2
• Windows Server 2003 x64 Edition Service Pack 2
• Windows Server 2003 with SP2 for Itanium-based Systems
-
MS10-060 (2265906)
Microsoft Security Bulletin MS10-060
[B]Vulnerabilities in the Microsoft .NET Common Language Runtime and in Microsoft Silverlight Could Allow Remote Code Execution[/B] (2265906)
[url]http://www.microsoft.com/technet/security/bulletin/MS10-060.mspx[/url]
[B]Âûïîëíåíèå ïðîèçâîëüíîãî êîäà â Microsoft .NET Framework è Silverlight[/B]
[url]http://www.securitylab.ru/vulnerability/396584.php[/url]
[B]Âûïîëíåíèå ïðîèçâîëüíîãî êîäà â Microsoft Silverlight 3[/B]
[url]http://www.securitylab.ru/vulnerability/396586.php[/url]
[B]Rating: [color=#CC0000]Critical[/color][/B]
[B]Îïèñàíèå:[/B]
Óÿçâèìîñòü ïîçâîëÿåò óäàëåííîìó ïîëüçîâàòåëþ âûïîëíèòü ïðîèçâîëüíûé êîä íà öåëåâîé ñèñòåìå.
Óÿçâèìîñòü ñóùåñòâóåò â .NET Framework ïðè îáðàáîòêå äåëåãèðîâàíèé âèðòóàëüíûõ ìåòîäîâ ñ ïîìîùüþ CLR (Common Language Runtime). Óäàëåííûé ïîëüçîâàòåëü ìîæåò ñ ïîìîùüþ ñïåöèàëüíî ñôîðìèðîâàííîãî .NET èëè Silverlight ïðèëîæåíèÿ âûïîëíèòü ïðîèçâîëüíûé êîä íà öåëåâîé ñèñòåìå.
Óÿçâèìîñòü ñóùåñòâóåò èç-çà îøèáêè ïðè îáðàáîòêå óêàçàòåëåé â Silverlight. Óäàëåííûé ïîëüçîâàòåëü ìîæåò ñ ïîìîùüþ ñïåöèàëüíî ñôîðìèðîâàííûõ äàííûõ âûçâàòü ïîâðåæäåíèå ïàìÿòè è âûïîëíèòü ïðîèçâîëüíûé êîä íà öåëåâîé ñèñòåìå.
[B][color=#CC0000]Affected Software[/color]:[/B]
• Windows XP, Windows XP x64[indent]• Microsoft .NET Framework 3.5
• Microsoft .NET Framework 2.0 Service Pack 2 and Microsoft .NET Framework 3.5 Service Pack 1[/indent]• Windows Server 2003, Windows Server 2003 x64, Windows Server 2003 for Itanium-based Systems[indent]• Microsoft .NET Framework 3.5
• Microsoft .NET Framework 2.0 Service Pack 2 and Microsoft .NET Framework 3.5 Service Pack 1[/indent]• Windows Vista, Windows Vista x64[indent]• Microsoft .NET Framework 2.0 Service Pack 1 and Microsoft .NET Framework 3.5
• Microsoft .NET Framework 2.0 Service Pack 2 and Microsoft .NET Framework 3.5 Service Pack 1[/indent]• Windows Server 2008, Windows Server 2008 for x64-based Systems, Windows Server 2008 for x64-based Systems[indent]• Microsoft .NET Framework 2.0 Service Pack 1 and Microsoft .NET Framework 3.5
• Microsoft .NET Framework 2.0 Service Pack 2 and Microsoft .NET Framework 3.5 Service Pack 1[/indent]• Windows 7[indent]• Microsoft .NET Framework 3.5.1[/indent]• Windows Server 2008 R2[indent]• Microsoft .NET Framework 3.5.1[/indent]
• Microsoft Silverlight 2
• Microsoft Silverlight 3
[B][color=#006600]Non-Affected Software[/color]:[/B]
• Microsoft .NET Framework 1.0 Service Pack 3
• Microsoft .NET Framework 1.1 Service Pack 1
• Microsoft .NET Framework 3.0
• Microsoft .NET Framework 3.0 Service Pack 1
• Microsoft .NET Framework 3.0 Service Pack 2
• Microsoft .NET Framework 3.5[indent]• Windows Vista Service Pack 2
• Windows Vista x64 Edition Service Pack 2
• Windows Server 2008 Service Pack 2
• Windows Server 2008 for x64-based Systems Service Pack 2
• Windows Server 2008 with SP2 for Itanium-based Systems[/indent]
• Microsoft .NET Framework 4.0
• Microsoft Silverlight 2
• Microsoft Silverlight 4
Page generated in 0.00886 seconds with 10 queries