Microsoft Windows OpenType压缩字体格式远程代码执行漏洞
CVE编号
CVE-2011-0033利用情况
暂无补丁情况
N/A披露时间
2011-02-11漏洞描述
Microsoft Windows是一款流行的操作系统。当解析OpenType字体中某些参数时Windows OpenType压缩字体格式(CFF)驱动存在一个输入验证错误。成功利用漏洞允许以内核上下文执行任意代码。解决建议
用户可参考如下供应商提供的安全补丁修复此漏洞:Microsoft Windows XP Media Center Edition SP3Microsoft WindowsXP-KB2485376-x86-ENU.exehttp://www.microsoft.com/downloads/details.aspx?familyid=F86E9E64-801A -431A-B24E-772011DFA66DMicrosoft Windows 7 for 32-bit Systems 0Microsoft Windows6.1-KB2485376-x86.msuhttp://www.microsoft.com/downloads/details.aspx?familyid=1DA57FBC-9EA4 -4FC4-911D-D5C7825E012CMicrosoft Windows Server 2003 Web Edition SP2Microsoft WindowsServer2003-KB2485376-x86-ENU.exehttp://www.microsoft.com/downloads/details.aspx?familyid=A99C2B13-DB81 -4F18-9CF7-C20614BA0132Microsoft Windows XP Professional x64 Edition SP2Microsoft WindowsServer2003.WindowsXP-KB2485376-x64-ENU.exehttp://www.microsoft.com/downloads/details.aspx?familyid=074396F0-A68C -4190-8DAC-0B883D56E3F1Microsoft Windows Vista x64 Edition SP1Microsoft Windows6.0-KB2485376-x64.msuhttp://www.microsoft.com/downloads/details.aspx?familyid=065AD8FE-1CAF -488E-A2E1-96DB29F2FA57Microsoft Windows Server 2008 for Itanium-based Systems SP2Microsoft Windows6.0-KB2485376-ia64.msuhttp://www.microsoft.com/downloads/details.aspx?familyid=91D5D34B-9D7E -4E83-89A4-F1AA388DC4E4Microsoft Windows 7 for x64-based Systems 0Microsoft Windows6.1-KB2485376-x64.msuhttp://www.microsoft.com/downloads/details.aspx?familyid=587ADB89-2F6A -4893-9906-B6D6D9ADA2BDMicrosoft Windows Server 2003 Standard Edition SP2Microsoft WindowsServer2003-KB2485376-x86-ENU.exehttp://www.microsoft.com/downloads/details.aspx?familyid=A99C2B13-DB81 -4F18-9CF7-C20614BA0132Microsoft Windows Server 2003 Itanium SP2Microsoft WindowsServer2003-KB2485376-ia64-ENU.exehttp://www.microsoft.com/downloads/details.aspx?familyid=BC09E42B-2EED -41B3-A03F-CB8CC94ADFEEMicrosoft Windows Server 2008 for Itanium-based Systems R2Microsoft Windows6.1-KB2485376-ia64.msuhttp://www.microsoft.com/downloads/details.aspx?familyid=4688EA0D-A467 -4F24-AC52-104D05C8CAE8Microsoft Windows Server 2008 for Itanium-based Systems 0Microsoft Windows6.0-KB2485376-ia64.msuhttp://www.microsoft.com/downloads/details.aspx?familyid=91D5D34B-9D7E -4E83-89A4-F1AA388DC4E4Microsoft Windows Vista x64 Edition SP2Microsoft Windows6.0-KB2485376-x64.msuhttp://www.microsoft.com/downloads/details.aspx?familyid=065AD8FE-1CAF -488E-A2E1-96DB29F2FA57受影响软件情况
# | 类型 | 厂商 | 产品 | 版本 | 影响面 | ||||
1 | |||||||||
---|---|---|---|---|---|---|---|---|---|
运行在以下环境 | |||||||||
系统 | microsoft | windows_2003_server | * | - | |||||
运行在以下环境 | |||||||||
系统 | microsoft | windows_7 | * | - | |||||
运行在以下环境 | |||||||||
系统 | microsoft | windows_7 | - | - | |||||
运行在以下环境 | |||||||||
系统 | microsoft | windows_server_2003 | * | - | |||||
运行在以下环境 | |||||||||
系统 | microsoft | windows_server_2008 | * | - | |||||
运行在以下环境 | |||||||||
系统 | microsoft | windows_server_2008 | - | - | |||||
运行在以下环境 | |||||||||
系统 | microsoft | windows_vista | * | - | |||||
运行在以下环境 | |||||||||
系统 | microsoft | windows_vista | - | - | |||||
运行在以下环境 | |||||||||
系统 | microsoft | windows_xp | * | - | |||||
运行在以下环境 | |||||||||
系统 | microsoft | windows_xp | - | - | |||||
- 攻击路径 网络
- 攻击复杂度 N/A
- 权限要求 无
- 影响范围 N/A
- 用户交互 需要
- 可用性 完全地
- 保密性 完全地
- 完整性 完全地
CWE-ID | 漏洞类型 |
CWE-20 | 输入验证不恰当 |
Exp相关链接

版权声明
本站原创文章转载请注明文章出处及链接,谢谢合作!
评论