Vulnerability Bulletins |
Ejecución arbitraria de código en Microsoft Windows |
|
Vulnerability classification |
|
| Property | Value |
| Confidence level | Oficial |
| Impact | Obtener acceso |
| Dificulty | Experto |
| Required attacker level | Acceso remoto sin cuenta a un servicio estandar |
System information |
|
| Property | Value |
| Affected manufacturer | Microsoft |
| Affected software |
Microsoft Windows 2000 SP4 Windows XP SP2 Windows XP Professional x64 Edition Windows Server 2003 SP1 Windows Server 2003 SP2 Windows Server 2003 x64 Edition Windows Server 2003 x64 Edition SP2 Windows Server 2003 SP1 for Itanium-based Systems Windows Server 2003 SP2 for Itanium-based Systems Windows Vista Windows Vista x64 Edition |
Description |
|
|
Se ha descubierto una vulnerabilidad en Microsoft WIndows. La vulnerabilidad reside en un error en el motor RPC Marshalling Engine. Un atacante remoto podría sobreescribir regiones de memoria arbitraria y ejeuctar código arbitrario mediante un mensaje RPC especialmente diseñado. |
|
Solution |
|
|
Actualización de software Microsoft Windows 2000 SP4 / patch Windows2000-KB970238-x86-enu Windows XP SP2 y SP3 / patch Windowsxp-KB970238-x86-enu Windows Server 2003 (x86/x64/Itanium) / patch Windowsserver2003-KB970238-x86-enu Windows Vista / patch Windows6.0-KB970238-x86-enu Windows Server 2008 (x86) / patch Windows6.0-KB970238-x86 Windows Server 2008 (x64) / patch Windows6.0-KB970238-x64 |
|
Standar resources |
|
| Property | Value |
| CVE | CVE-2009-0568 |
| BID | |
Other resources |
|
|
Microsoft Security Bulletin (MS09-026) http://www.microsoft.com/technet/security/Bulletin/MS09-026.mspx |
|
Version history |
||
| Version | Comments | Date |
| 1.0 | Aviso emitido | 2009-06-15 |






