int(4602)

Vulnerability Bulletins


Ejecución remota de código en Microsoft DirectX 8 y 9

Vulnerability classification

Property Value
Confidence level Oficial
Impact Obtener acceso
Dificulty Experto
Required attacker level Acceso remoto sin cuenta a un servicio estandar

System information

Property Value
Affected manufacturer Microsoft
Affected software Microsoft DirectX 8 y 9

Description

Se ha descubierto una vulnerabilidad en Microsoft DirectX 8.1 y 9.0. La vulnerabilidad reside en un error en la descompresión de ficheros multimedia.

Un atacante remoto podría ejecutar código arbitrario mediante un fichero MJPEG especialmente diseñado.

El boletín MS09-011 sustituye al MS08-033.

Solution



Actualización de software

Microsoft (MS09-011)
Microsoft Windows 2000 Service Pack 4 / patch Windows2000-DirectX8-KB961373-x86-ENU
Windows XP Service Pack 2 y Windows XP Service Pack 3 / patch WindowsXP-DirectX9-KB961373-x86-ENU
Windows XP Professional x64 Edition y Windows XP Professional x64 Edition Service Pack 2 / patch WindowsServer2003.WindowsXP-DirectX9-KB961373-x64-ENU
Windows Server 2003 Service Pack 1 y Windows Server 2003 Service Pack 2 / patch WindowsServer2003-DirectX9-KB961373-x86-ENU
Windows Server 2003 x64 Edition y Windows Server 2003 x64 Edition Service Pack 2 / patch WindowsServer2003-DirectX9-KB961373-x86-ENU
Windows Server 2003 with SP1 para Itanium-based Systems y Windows Server 2003 with SP2 para Itanium-based Systems / patch WindowsServer2003-DirectX9-KB961373-ia64-ENU
http://www.microsoft.com/downloads

Standar resources

Property Value
CVE CVE-2009-0084
BID

Other resources

Microsoft Security Bulletin (MS09-011)
http://www.microsoft.com/technet/security/bulletin/MS09-011.mspx

Version history

Version Comments Date
1.0 Aviso emitido 2009-04-15