Microsoft ListBox/ComboBox Control User32.dll函数缓冲区溢出漏洞

漏洞信息详情

Microsoft ListBox/ComboBox Control User32.dll函数缓冲区溢出漏洞

漏洞简介

Windows NT到Server 2003版本中User32.dll文件的一个函数存在缓冲区溢出漏洞。本地用户可以通过可享有特权应用程序中超长的(1) ListBox的LB_DIR消息或 (2) ComboBox的CB_DIR消息执行任意代码。

漏洞公告

Microsoft has released a patch that will address this issue.
Microsoft has released updated information concerning Microsoft Security Bulletin MS03-045. Microsoft has reported that a compatibility problem with an unspecified third party software has been identified with a set of language specific versions of the Windows 2000 Service Pack 4 patch. However, this problem is unrelated to the security vulnerability discussed in MS03-045. Customers who have applied the patch are protected against the vulnerability discussed in this bulletin. The vendor has released new information to reflect the availability of the updated patch for specific languages. Please see the referenced Microsoft Security Bulletin MS03-045 for more information.
Revision 2.0 of the bulletin was also released to provide updated patches for Windows XP to address an unrelated problem with Debug Programs (SeDebugPrivilege). These patches can be found in the same location as the initial patches. Please see the updated bulletin for further details.
Microsoft Windows 2000 Server SP2

Microsoft Windows 2000 Advanced Server SP2

Microsoft Windows Server 2003 Enterprise Edition Itanium 0

Microsoft Windows Server 2003 Standard Edition

Microsoft Windows Server 2003 Datacenter Edition Itanium 0

Microsoft Windows XP 64-bit Edition SP1

Microsoft Windows Server 2003 Datacenter Edition

Microsoft Windows 2000 Advanced Server SP4

Microsoft Windows 2000 Professional SP3

Microsoft Windows Server 2003 Enterprise Edition

Microsoft Windows 2000 Professional SP2

Microsoft Windows 2000 Datacenter Server SP4

Microsoft Windows Server 2003 Web Edition

Microsoft Windows 2000 Advanced Server SP3

Microsoft Windows XP Embedded SP1

Microsoft Windows XP Home SP1

Microsoft Windows 2000 Datacenter Server SP3

Microsoft Windows 2000 Server SP3

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享