Microsoft Windows OpenType压缩字体格式远程代码执行漏洞

admin 2023-12-09 02:21:19 Ali_nvd 来源:ZONE.CI 全球网 0 阅读模式
Microsoft Windows OpenType压缩字体格式远程代码执行漏洞

CVE编号

CVE-2011-0033

利用情况

暂无

补丁情况

N/A

披露时间

2011-02-11
漏洞描述
Microsoft Windows是一款流行的操作系统。当解析OpenType字体中某些参数时Windows OpenType压缩字体格式(CFF)驱动存在一个输入验证错误。成功利用漏洞允许以内核上下文执行任意代码。
解决建议
用户可参考如下供应商提供的安全补丁修复此漏洞:Microsoft Windows XP Media Center Edition SP3Microsoft WindowsXP-KB2485376-x86-ENU.exehttp://www.microsoft.com/downloads/details.aspx?familyid=F86E9E64-801A -431A-B24E-772011DFA66DMicrosoft Windows 7 for 32-bit Systems 0Microsoft Windows6.1-KB2485376-x86.msuhttp://www.microsoft.com/downloads/details.aspx?familyid=1DA57FBC-9EA4 -4FC4-911D-D5C7825E012CMicrosoft Windows Server 2003 Web Edition SP2Microsoft WindowsServer2003-KB2485376-x86-ENU.exehttp://www.microsoft.com/downloads/details.aspx?familyid=A99C2B13-DB81 -4F18-9CF7-C20614BA0132Microsoft Windows XP Professional x64 Edition SP2Microsoft WindowsServer2003.WindowsXP-KB2485376-x64-ENU.exehttp://www.microsoft.com/downloads/details.aspx?familyid=074396F0-A68C -4190-8DAC-0B883D56E3F1Microsoft Windows Vista x64 Edition SP1Microsoft Windows6.0-KB2485376-x64.msuhttp://www.microsoft.com/downloads/details.aspx?familyid=065AD8FE-1CAF -488E-A2E1-96DB29F2FA57Microsoft Windows Server 2008 for Itanium-based Systems SP2Microsoft Windows6.0-KB2485376-ia64.msuhttp://www.microsoft.com/downloads/details.aspx?familyid=91D5D34B-9D7E -4E83-89A4-F1AA388DC4E4Microsoft Windows 7 for x64-based Systems 0Microsoft Windows6.1-KB2485376-x64.msuhttp://www.microsoft.com/downloads/details.aspx?familyid=587ADB89-2F6A -4893-9906-B6D6D9ADA2BDMicrosoft Windows Server 2003 Standard Edition SP2Microsoft WindowsServer2003-KB2485376-x86-ENU.exehttp://www.microsoft.com/downloads/details.aspx?familyid=A99C2B13-DB81 -4F18-9CF7-C20614BA0132Microsoft Windows Server 2003 Itanium SP2Microsoft WindowsServer2003-KB2485376-ia64-ENU.exehttp://www.microsoft.com/downloads/details.aspx?familyid=BC09E42B-2EED -41B3-A03F-CB8CC94ADFEEMicrosoft Windows Server 2008 for Itanium-based Systems R2Microsoft Windows6.1-KB2485376-ia64.msuhttp://www.microsoft.com/downloads/details.aspx?familyid=4688EA0D-A467 -4F24-AC52-104D05C8CAE8Microsoft Windows Server 2008 for Itanium-based Systems 0Microsoft Windows6.0-KB2485376-ia64.msuhttp://www.microsoft.com/downloads/details.aspx?familyid=91D5D34B-9D7E -4E83-89A4-F1AA388DC4E4Microsoft Windows Vista x64 Edition SP2Microsoft Windows6.0-KB2485376-x64.msuhttp://www.microsoft.com/downloads/details.aspx?familyid=065AD8FE-1CAF -488E-A2E1-96DB29F2FA57
参考链接
http://osvdb.org/70821
http://secunia.com/advisories/43252
http://support.avaya.com/css/P8/documents/100127239
http://www.securityfocus.com/bid/46106
http://www.securitytracker.com/id?1025034
http://www.vupen.com/english/advisories/2011/0320
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-007
https://exchange.xforce.ibmcloud.com/vulnerabilities/64906
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.ova...
受影响软件情况
# 类型 厂商 产品 版本 影响面
1
运行在以下环境
系统 microsoft windows_2003_server * -
运行在以下环境
系统 microsoft windows_7 * -
运行在以下环境
系统 microsoft windows_7 - -
运行在以下环境
系统 microsoft windows_server_2003 * -
运行在以下环境
系统 microsoft windows_server_2008 * -
运行在以下环境
系统 microsoft windows_server_2008 - -
运行在以下环境
系统 microsoft windows_vista * -
运行在以下环境
系统 microsoft windows_vista - -
运行在以下环境
系统 microsoft windows_xp * -
运行在以下环境
系统 microsoft windows_xp - -
CVSS3评分 9.3
  • 攻击路径 网络
  • 攻击复杂度 N/A
  • 权限要求 无
  • 影响范围 N/A
  • 用户交互 需要
  • 可用性 完全地
  • 保密性 完全地
  • 完整性 完全地
AV:N/AC:M/Au:N/C:C/I:C/A:C
CWE-ID 漏洞类型
CWE-20 输入验证不恰当
- avd.aliyun.com
weinxin
版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
N/A Ali_nvd

N/A

N/ACVE编号 CVE-2024-9120利用情况 暂无补丁情况 N/A披露时间 2024-09-23漏洞描述Use after free in Dawn
评论:0   参与:  0