Boletines de Vulnerabilidades |
Ejecución de código a través de Vector Markup Language |
|
Clasificación de la vulnerabilidad |
|
Propiedad | Valor |
Nivel de Confianza | Oficial |
Impacto | Obtener acceso |
Dificultad | Experto |
Requerimientos del atacante | Acceso remoto sin cuenta a un servicio exotico |
Información sobre el sistema |
|
Propiedad | Valor |
Fabricante afectado | Microsoft |
Software afectado |
Microsoft Windows 2000 Service Pack 4 Microsoft Windows XP Service Pack 2 Microsoft Windows XP Professional x64 Edition Microsoft Windows Server 2003 Microsoft Windows Server 2003 Service Pack 1 Microsoft Windows Server 2003 x64 Edition Internet Explorer <= 7.0 |
Descripción |
|
Se ha descubierto una vulnerabilidad en Vector Markup Language (VML) implementado en Microsoft Windows. La vulnerabilidad reside en un error no especificado. Un atacante remoto podría ejecutar código arbitrario y tomar el control de la máquina mediante la construcción de una página Web o el envío de un correo electrónico que contenga código HTML. |
|
Solución |
|
Actualización de software Microsoft Microsoft Windows Microsoft Windows 2000 Service Pack 4 Microsoft Windows XP Service Pack 2 http://www.microsoft.com/downloads/details.aspx?FamilyId=81FB6A72-AC8A-4B28-905F-A44691D69432 Microsoft Windows XP Professional x64 Edition http://www.microsoft.com/downloads/details.aspx?FamilyId=D06FD167-4F3E-4A2C-B52C-7426DDAD6828 Microsoft Windows Server 2003 Microsoft Windows Server 2003 Service Pack 1 http://www.microsoft.com/downloads/details.aspx?FamilyId=4FEE481F-DACE-4EAC-9AFE-BC28ADD70CC5 Microsoft Windows Server 2003 / Itanium-based Systems Microsoft Windows Server 2003 with SP1 / Itanium-based Systems http://www.microsoft.com/downloads/details.aspx?FamilyId=C517FB85-128E-43DB-A659-38AF32283716 Microsoft Windows Server 2003 x64 Edition http://www.microsoft.com/downloads/details.aspx?FamilyId=FF4A1F24-C1E9-4223-965B-14C4793AAF96 Internet Explorer Internet Explorer 5.01 Service Pack 4 / Microsoft Windows 2000 Service Pack 4 http://www.microsoft.com/downloads/details.aspx?FamilyId=B1C7F765-772C-4EEB-9438-BC820CB929E1 Internet Explorer 6 Service Pack 1 / Microsoft Windows 2000 Service Pack 4 http://www.microsoft.com/downloads/details.aspx?FamilyId=922A3569-85D1-4584-9B84-4AA7304C69BB Internet Explorer 7 / Microsoft Windows XP Service Pack 2 http://www.microsoft.com/downloads/details.aspx?FamilyId=55A0A6EC-FEFA-40BB-BB6B-3AAB50275A73 Internet Explorer 7 / Microsoft Windows XP Professional x64 Edition http://www.microsoft.com/downloads/details.aspx?FamilyId=B5A8B1F2-6AF0-4F03-989C-C8DE2EACE71D Internet Explorer 7 / Microsoft Windows Server 2003 Internet Explorer 7 / Microsoft Windows Server 2003 Service Pack 1 http://www.microsoft.com/downloads/details.aspx?FamilyId=08E5CD2E-55C0-4AC9-859F-1B24497B31CE Internet Explorer 7 / Microsoft Windows Server 2003 / Itanium-based Systems Internet Explorer 7 / Microsoft Windows Server 2003 with SP1 / Itanium-based Systems http://www.microsoft.com/downloads/details.aspx?FamilyId=48B4D271-D494-4A5C-ABA8-11B3B4584902 Internet Explorer 7 / Microsoft Windows Server 2003 x64 Edition http://www.microsoft.com/downloads/details.aspx?FamilyId=F9C3E0DE-DB66-4D83-829F-C93052BDB1FA |
|
Identificadores estándar |
|
Propiedad | Valor |
CVE | CVE-2007-0024 |
BID | |
Recursos adicionales |
|
Microsoft Security Bulletin (MS07-004) http://www.microsoft.com/technet/security/Bulletin/MS07-004.mspx |
Histórico de versiones |
||
Versión | Comentario | Fecha |
1.0 | Aviso emitido | 2007-01-10 |