Microsoft Internet Explorer mstime.dll释放后使用漏洞

admin 2022-07-16 17:18:45 CNNVD漏洞 来源:ZONE.CI 全球网 0 阅读模式

漏洞信息详情

Microsoft Internet Explorer mstime.dll释放后使用漏洞

  • CNNVD编号:CNNVD-201003-506
  • 危害等级: 超危
  • CVE编号: CVE-2010-0492
  • 漏洞类型: 代码注入
  • 发布时间: 2010-03-31
  • 威胁类型: 远程
  • 更新时间: 2021-07-27
  • 厂        商: microsoft
  • 漏洞来源:

漏洞简介

Microsoft Internet Explorer是美国微软(Microsoft)公司发布的Windows操作系统中默认捆绑的Web浏览器。

Microsoft Internet Explorer 8中的mstime.dll中存在释放后使用漏洞。远程攻击者可借助与TIME2行为,CTimeAction对象和标记破坏有关的向量执行任意代码,导致内存破坏。

漏洞公告

目前厂商已经发布了升级补丁以修复此安全问题,补丁获取链接:

Microsoft Internet Explorer 8

Microsoft Cumulative Security Update for Internet Explorer 8 in Windows 7 x64 Edition (KB980182)

http://www.microsoft.com/downloads/details.aspx?familyid=6172dbec-6bfc -40bd-a0d4-67c39fb41b87

Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Vista x64 Edition (KB980182)

http://www.microsoft.com/downloads/details.aspx?familyid=50809cc3-6baa -41b4-ba0a-596a1dd846ed

Microsoft Cumulative Security Update for Internet Explorer 8 for Windows XP x64 Edition (KB980182)

http://www.microsoft.com/downloads/details.aspx?familyid=284d70ea-24a3 -4e67-a2a8-e9f272f728db

Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Vista (KB980182)

http://www.microsoft.com/downloads/details.aspx?familyid=c9584689-5196 -4840-927c-23c8038f3382

Microsoft Cumulative Security Update for Internet Explorer 8 for Windows XP (KB980182)

http://www.microsoft.com/downloads/details.aspx?familyid=46172617-293a -44c7-95b6-18202ab06a41

Microsoft Cumulative Security Update for Internet Explorer 8 in Windows 7 (KB980182)

http://www.microsoft.com/downloads/details.aspx?familyid=c0145563-428e -47b6-b245-b59dce88ac0e

Microsoft Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB980182)

http://www.microsoft.com/downloads/details.aspx?familyid=5201a0c5-8162 -4809-b9d1-0e972b0f0066

Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 for Itanium-based Syste

http://www.microsoft.com/downloads/details.aspx?familyid=82fa6f47-002f -4943-888c-2e852675e76e

Microsoft Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 (KB980182)

http://www.microsoft.com/downloads/details.aspx?familyid=53fc3285-63c4 -487f-ad9a-7e1673aeffc7

Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 x64 Edition (KB980182)

http://www.microsoft.com/downloads/details.aspx?familyid=8b7c664b-8612 -458f-bd0a-cf28b67f8374

Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 (KB980182)

http://www.microsoft.com/downloads/details.aspx?familyid=c69a6dfe-66b1 -4426-96a5-d64000296e76

Microsoft Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB980182)

http://www.microsoft.com/downloads/details.aspx?familyid=e16c10d2-896d -48f3-bc76-5fa70881396a

参考网址

来源:http://nvd.nist.gov/nvd.cfm?cvename=CVE-2010-0492

链接:无

来源:MS

链接:https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-018

来源:BID

链接:http://www.securityfocus.com/bid/39030

来源:OVAL

链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7722

来源:MISC

链接:http://www.zerodayinitiative.com/advisories/ZDI-10-033

来源:CERT

链接:http://www.us-cert.gov/cas/techalerts/TA10-068A.HTML

来源:SECTRACK

链接:http://securitytracker.com/id?1023773

来源:VUPEN

链接:http://www.vupen.com/english/advisories/2010/0744

来源:BUGTRAQ

链接:http://www.securityfocus.com/archive/1/510506/100/0/threaded

来源:BID

链接:https://www.securityfocus.com/bid/39030

来源:CERT

链接:http://www.us-cert.gov/cas/techalerts/TA10-089A.HTML

受影响实体

  • Microsoft Ie:8  
  • Microsoft Ie:8.0.6001  

补丁

  • Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 x64 Edition (KB980182)
  • Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 x64 Edition (KB980182)
  • Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 R2 for Itanium-based Systems (KB980182)
  • Cumulative Security Update for Internet Explorer 8 for Windows Server 2003 (KB980182)
  • Cumulative Security Update for Internet Explorer 8 in Windows Server 2008 (KB980182)

weinxin
特别声明
本站(ZONE.CI)所有文章仅供技术研究,若将其信息做其他用途,由用户承担全部法律及连带责任,本站不承担任何法律及连带责任,请遵守中华人民共和国安全法.
评论:0   参与:  0