Vulnerability Bulletins |
Obtención de acceso en Microsoft Visual Studio y Microsoft Visual C++ |
|
Vulnerability classification |
|
| Property | Value |
| Confidence level | Oficial |
| Impact | Obtener acceso |
| Dificulty | Experto |
| Required attacker level | Acceso remoto sin cuenta a un servicio estandar |
System information |
|
| Property | Value |
| Affected manufacturer | Microsoft |
| Affected software |
Microsoft Visual Studio .NET 2003 SP1 Microsoft Visual Studio 2005 SP1 Microsoft Visual Studio 2008 SP1 Microsoft Visual Studio 2010 Microsoft Visual C++ 2005 SP1 Redistributable Package Microsoft Visual C++ 2008 SP1 Redistributable Package Microsoft Visual C++ 2010 Redistributable Package |
Description |
|
|
- CVE-2010-3190: Se ha descubierto una vulnerabilidad en Microsoft Visual Studio y Microsoft Visual C++. La vulnerabilidad reside en la manera en la que ciertas aplicaciones desarrolladas con Microsoft Foundation Classes manejan la carga de archivos DLL. Un atacante remoto podría obtener acceso al sistema mediante métodos no especificados. |
|
Solution |
|
|
Actualización de software Microsoft (MS11-025) Ver tabla de actualizaciones en: http://www.microsoft.com/technet/security/Bulletin/MS11-025.mspx |
|
Standar resources |
|
| Property | Value |
| CVE | CVE-2010-3190 |
| BID | |
Other resources |
|
|
Microsoft Security Bulletin (MS11-025) http://www.microsoft.com/technet/security/Bulletin/MS11-025.mspx |
|
Version history |
||
| Version | Comments | Date |
| 1.0 | Aviso emitido | 2011-04-14 |






