int(4200)

Vulnerability Bulletins


Ejecución de código en Windows Media Encoder 9 Series

Vulnerability classification

Property Value
Confidence level Oficial
Impact Obtener acceso
Dificulty Experto
Required attacker level Acceso remoto sin cuenta a un servicio estandar

System information

Property Value
Affected manufacturer Microsoft
Affected software Windows Media Encoder 9 Series

Description

Se ha descubierto una vulnerabilidad de tipo desbordamiento de búfer en Windows Media Encoder 9 Series. La vulnerabilidad reside en un error de comprobación de límites en el control ActiveX "WMEX.DLL".

Un atacante remoto podría ejecutar código arbitrario mediante una página Web especialmente diseñada.

Solution



Actualización de software

Microsoft (MS08-053)
Windows Media Encoder 9 Series / Microsoft Windows 2000 Service Pack 4 / patch WindowsMedia9-KB954156-x86-EN
Windows Media Encoder 9 Series / Windows XP Service Pack y Service Pack 3 / patch
WindowsMedia9-KB954156-x86-ENU
Windows Media Encoder 9 Series / Windows Server 2003 Service Pack 1 y Service Pack 2 / patch WindowsMedia9-KB954156-x86-ENU
Windows Media Encoder 9 Series x64 Edition / Windows Server 2003 x64 Edition y Service Pack 2 / patch WindowsMedia9-KB954156-x64-ENU
Windows Media Encoder 9 Series / Windows Server 2003 x64 Edition y Service Pack 2 / patch WindowsMedia9-KB954156-32bit-x64-ENU /quiet
Windows Media Encoder 9 Series / Windows Vista y Vista Service Pack 1 / patch WindowsMedia9-KB954156-INTL
Windows Media Encoder 9 Series x64 Edition / Windows Vista x64 Edition y Service Pack 1 / patch WindowsMedia9-KB954156-x64-INTL
Windows Media Encoder 9 Series / Windows Vista x64 Edition y Service Pack 1 / patch WindowsMedia9-KB954156-INTL
Windows Media Encoder 9 Series / Windows Server 2008 32-bit Systems / patch WindowsMedia9-KB954156-INTL
Windows Media Encoder 9 Series x64 Edition / Windows Server 2008 x64-based Systems / patch WindowsMedia9-KB954156-x64-INTL
Windows Media Encoder 9 Series / Windows Server 2008 x64-based Systems / patch WindowsMedia9-KB954156-INTL
http://www.microsoft.com/downloads

Hewlett-Packard
Ver tabla de actualizaciones en:
http://www12.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01560892-1
http://www.itrc.hp.com/service/patch/mainPage.do

Standar resources

Property Value
CVE CVE-2008-3008
BID 31065

Other resources

Microsoft Security Bulletin (MS08-053)
http://www.microsoft.com/technet/security/bulletin/ms08-053.mspx

HP SECURITY BULLETIN (HPSBST02372)
http://www12.itrc.hp.com/service/cki/docDisplay.do?docId=emr_na-c01560892-1

Version history

Version Comments Date
1.0 Aviso emitido 2008-09-10
1.1 Aviso emitido por HP (HPSBST02372) 2008-09-25
Ministerio de Defensa
CNI
CCN
CCN-CERT