Windows OLE Processing Error Lets Remote Users Cause Arbitary Code to Be Executed on the Target User's System
|
|
SecurityTracker Alert ID: 1026418 |
|
SecurityTracker URL: http://securitytracker.com/id/1026418
|
|
CVE Reference:
CVE-2011-3400
(Links to External Site)
|
Date: Dec 13 2011
|
Impact:
Execution of arbitrary code via network, User access via network
|
Fix Available: Yes Vendor Confirmed: Yes
|
Version(s): XP SP3, 2003 SP2; and prior service packs
|
Description:
A vulnerability was reported in Microsoft Windows Object Linking and Embedding (OLE). A remote user can cause arbitrary code to be executed on the target user's system.
The system does not properly process OLE objects in memory. A remote user can create a file containing a specially crafted OLE object that, when loaded by the target user, will execute arbitrary code on the target system. The code will run with the privileges of the target user.
An anonymous researcher reported this vulnerability via iDefense.
|
Impact:
A remote user can create a file that, when loaded by the target user, will execute arbitrary code on the target user's system.
|
Solution:
The vendor has issued the following fixes:
Windows XP Service Pack 3:
http://www.microsoft.com/downloads/details.aspx?familyid=73531165-f299-4b62-b738-52fca410eaae
Windows XP Professional x64 Edition Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=a98bb7cf-9939-4927-8d21-ccb3845e7cb7
Windows Server 2003 Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=6b555040-1117-4b06-a48c-02f0e1b686d8
Windows Server 2003 x64 Edition Service Pack 2:
http://www.microsoft.com/downloads/details.aspx?familyid=eb17782c-f754-42ab-905b-6f141df008c3
Windows Server 2003 with SP2 for Itanium-based Systems:
http://www.microsoft.com/downloads/details.aspx?familyid=4cdde8a9-6d44-41fa-82c0-a25404cdfbb5
A restart may be required.
The Microsoft advisory is available at:
http://technet.microsoft.com/en-us/security/bulletin/ms11-093
|
Vendor URL: technet.microsoft.com/en-us/security/bulletin/ms11-093 (Links to External Site)
|
Cause:
Access control error
|
Underlying OS:
|
|
Message History:
None.
|
Source Message Contents
|
|
|
[Original Message Not Available for Viewing]
|
|