int(5328)

Vulnerability Bulletins


Ejecución remota de código en Internet Information Services (IIS)

Vulnerability classification

Property Value
Confidence level Oficial
Impact Obtener acceso
Dificulty Experto
Required attacker level Acceso remoto sin cuenta a un servicio estandar

System information

Property Value
Affected manufacturer Microsoft
Affected software Windows Server 2003
Windows Vista
Windows Server 2008
Windows 7
Windows Server 2008 R2

Description

Se ha encontrado una vulnerabilidad en Internet Information Services 6.0, 7.0, y 7.5. La vulnerabilidad reside en un error al parsear información sobre la autenticación.

Un atacante remoto podría ejecutar código mediante métodos no especificados relativos a "token checking" que provoca una corrupción de memoria.

Solution



Actualización de software

Microsoft (MS10-040)
Windows Server 2003 SP2 / Internet Information Services 6.0 / patch WindowsServer2003-KB982666-x86-ENU
Windows Server 2003 x64 SP2 / Internet Information Services 6.0 / patch WindowsServer2003.WindowsXP-KB982666-x64-ENU
Windows Server 2003 SP2 para Itanium-based / Internet Information Services 6.0 / patch WindowsServer2003-KB982666-ia64-ENU
Windows Vista SP1 y Windows Vista SP2 / Internet Information Services 7.0 / patch Windows6.0-KB982666-x86
Windows Vista x64 SP1 y Windows Vista x64 SP2 / Internet Information Services 7.0 / patch Windows6.0-KB982666-x64
Windows Server 2008 para 32-bit SP2 / Internet Information Services 7.0 / patch Windows6.0-KB982666-x86
Windows Server 2008 para x64 SP2 / Internet Information Services 7.0 / patch Windows6.0-KB982666-x64
Windows Server 2008 para Itanium-based SP2 / Internet Information Services 7.0 / patch Windows6.0-KB982666-ia64
Windows 7 para 32-bit / Internet Information Services 7.5 / patch Windows6.1-KB982666-x86
Windows 7 para x64 / Internet Information Services 7.5 / patch Windows6.1-KB982666-x64
Windows Server 2008 R2 para x64 / Internet Information Services 7.5 / patch Windows6.1-KB982666-x64
Windows Server 2008 R2 para Itanium-based / Internet Information Services 7.5 / patch Windows6.1-KB982666-ia64
http://www.microsoft.com/downloads

Standar resources

Property Value
CVE CVE-2010-1256
BID

Other resources

Microsoft Security Bulletin (MS10-040)
http://www.microsoft.com/technet/security/bulletin/MS10-040.mspx

Version history

Version Comments Date
1.0 Aviso emitido 2010-06-09
Ministerio de Defensa
CNI
CCN
CCN-CERT