Microsoft Windows SMB Transaction Parser 输入验证漏洞

admin 2023-12-09 00:24:21 Ali_nvd 来源:ZONE.CI 全球网 0 阅读模式
Microsoft Windows SMB Transaction Parser 输入验证漏洞

CVE编号

CVE-2011-0661

利用情况

暂无

补丁情况

N/A

披露时间

2011-04-14
漏洞描述
Microsoft Windows是一款流行的操作系统。Microsoft Windows在处理SMB报文某些字段时存在错误,向目标服务器提交特制的SMB报文,可以服务进程上下文执行任意代码。
解决建议
用户可参考如下供应商提供的安全公告获得补丁信息:Microsoft Windows XP Media Center Edition SP3Microsoft WindowsXP-KB2508429-x86-ENU.exehttp://www.microsoft.com/downloads/details.aspx?familyid=CCB08A8A-F4D9 -4320-8FFB-3FD4FE217987Microsoft Windows 7 for 32-bit Systems 0Microsoft Windows6.1-KB2508429-x86.msuhttp://www.microsoft.com/downloads/details.aspx?familyid=D3EF905B-3584 -4842-9EC2-CF3856305D49Microsoft Windows Server 2003 Web Edition SP2Microsoft WindowsServer2003-KB2508429-x86-ENU.exehttp://www.microsoft.com/downloads/details.aspx?familyid=64C550D4-C927 -4382-91E1-473ED6790819Microsoft Windows XP Professional x64 Edition SP2Microsoft WindowsServer2003.WindowsXP-KB2508429-x64-ENU.exehttp://www.microsoft.com/downloads/details.aspx?familyid=7EE202DA-A711 -42EE-BEA3-7202A70E4EA0Microsoft Windows Vista x64 Edition SP1Microsoft Windows6.0-KB2508429-x64.msuhttp://www.microsoft.com/downloads/details.aspx?familyid=2878C587-6544 -40B4-9288-FC3B3CE1128DMicrosoft Windows Server 2008 for Itanium-based Systems SP2Microsoft Windows6.0-KB2508429-ia64.msuhttp://www.microsoft.com/downloads/details.aspx?familyid=B89B8E28-CD98 -4BCC-8729-5E51D52D1E92Microsoft Windows 7 for x64-based Systems 0Microsoft Windows6.1-KB2508429-x64.msuhttp://www.microsoft.com/downloads/details.aspx?familyid=7DDC943B-6868 -4E8F-A869-89B47133C287Microsoft Windows Server 2003 Standard Edition SP2Microsoft WindowsServer2003-KB2508429-x86-ENU.exehttp://www.microsoft.com/downloads/details.aspx?familyid=64C550D4-C927 -4382-91E1-473ED6790819Microsoft Windows Server 2003 Itanium SP2Microsoft WindowsServer2003-KB2508429-ia64-ENU.exehttp://www.microsoft.com/downloads/details.aspx?familyid=79AEB3CD-7C73 -467B-B91E-02C6EA01E911Microsoft Windows Server 2008 for Itanium-based Systems R2Microsoft Windows6.1-KB2508429-ia64.msuhttp://www.microsoft.com/downloads/details.aspx?familyid=0005377B-443F -44CA-A890-620B2DCEA6F1Microsoft Windows Server 2008 for Itanium-based Systems 0Microsoft Windows6.0-KB2508429-ia64.msuhttp://www.microsoft.com/downloads/details.aspx?familyid=B89B8E28-CD98 -4BCC-8729-5E51D52D1E92Microsoft Windows Vista x64 Edition SP2Microsoft Windows6.0-KB2508429-x64.msuhttp://www.microsoft.com/downloads/details.aspx?familyid=2878C587-6544 -40B4-9288-FC3B3CE1128D
参考链接
http://osvdb.org/71781
http://secunia.com/advisories/44072
http://www.securityfocus.com/bid/47198
http://www.securitytracker.com/id?1025329
http://www.us-cert.gov/cas/techalerts/TA11-102A.html
http://www.vupen.com/english/advisories/2011/0939
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-020
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
受影响软件情况
# 类型 厂商 产品 版本 影响面
1
运行在以下环境
系统 microsoft windows_2003_server * -
运行在以下环境
系统 microsoft windows_7 - -
运行在以下环境
系统 microsoft windows_server_2003 * -
运行在以下环境
系统 microsoft windows_server_2008 * -
运行在以下环境
系统 microsoft windows_server_2008 - -
运行在以下环境
系统 microsoft windows_server_2008 r2 -
运行在以下环境
系统 microsoft windows_vista * -
运行在以下环境
系统 microsoft windows_xp * -
运行在以下环境
系统 microsoft windows_xp - -
CVSS3评分 10.0
  • 攻击路径 网络
  • 攻击复杂度 低
  • 权限要求 无
  • 影响范围 N/A
  • 用户交互 无
  • 可用性 完全地
  • 保密性 完全地
  • 完整性 完全地
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-ID 漏洞类型
CWE-20 输入验证不恰当
- avd.aliyun.com
weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
N/A Ali_nvd

N/A

N/ACVE编号 CVE-2024-9120利用情况 暂无补丁情况 N/A披露时间 2024-09-23漏洞描述Use after free in Dawn
评论:0   参与:  0