Microsoft IIS 安全漏洞

漏洞信息详情

Microsoft IIS 安全漏洞

漏洞简介

Microsoft Internet Information Services(IIS)是美国微软(Microsoft)公司的一款适用于Windows Server平台的Web服务器。

Microsoft IIS 服务程序对于进程外运行的应用进程的权限处理上存在漏洞,攻击者可能利用这个漏洞进行权限提升攻击。 默认设置hosting进程(dllhost.exe)一般以IWAM_computername帐户的安全上下文运行,在某些情况下hosting进程可能象IIS ISAPI扩展一样以LocalSystem权限执行应用程序。 不过只有已经能够在受影响的web server中上载和执行应用程序的攻击者才能利用本漏洞。正常安全实践不建议允许不可信用户在服务器中上载应用程序,即使可信用户的应用程序也须在上载前进行仔细检查。

漏洞公告

厂商补丁:

Microsoft

———

Microsoft已经为此发布了一个安全公告(MS02-062)以及相应补丁:

MS02-062:Cumulative Patch for Internet Information Service (Q327696)

链接:
http://www.microsoft.com/technet/security/bulletin/MS02-062.asp” target=”_blank”>


http://www.microsoft.com/technet/security/bulletin/MS02-062.asp

补丁下载:

* IIS 4.0:


http://www.microsoft.com/Downloads/Release.asp?ReleaseID=43566” target=”_blank”>


http://www.microsoft.com/Downloads/Release.asp?ReleaseID=43566

* IIS 5.0:


http://www.microsoft.com/Downloads/Release.asp?ReleaseID=43296” target=”_blank”>


http://www.microsoft.com/Downloads/Release.asp?ReleaseID=43296

* IIS 5.1:

32-bit:


http://www.microsoft.com/Downloads/Release.asp?ReleaseID=43578” target=”_blank”>


http://www.microsoft.com/Downloads/Release.asp?ReleaseID=43578

64-bit:


http://www.microsoft.com/Downloads/Release.asp?ReleaseID=43602” target=”_blank”>


http://www.microsoft.com/Downloads/Release.asp?ReleaseID=43602

参考网址

来源:CIAC

链接:http://www.ciac.org/ciac/bulletins/n-011.shtml

来源:MS

链接:https://docs.microsoft.com/en-us/security-updates/securitybulletins/2002/ms02-062

来源:XF

链接:http://www.iss.net/security_center/static/10502.php

来源:VULNWATCH

链接:http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0059.html

来源:MISC

链接:http://www.li0n.pe.kr/eng/advisory/ms/iis_impersonation.txt

来源:OVAL

链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A930

来源:OVAL

链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A983

来源:BUGTRAQ

链接:http://marc.info/?l=bugtraq&m=103642839205574&w=2

来源:OVAL

链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A929

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享