漏洞信息详情
Windows Shell远程任意代码执行漏洞(MS04-024)
- CNNVD编号:CNNVD-200407-006
- 危害等级: 超危
- CVE编号:
CVE-2004-0420
- 漏洞类型:
设计错误
- 发布时间:
2004-07-07
- 威胁类型:
远程
- 更新时间:
2005-10-20
- 厂 商:
microsoft - 漏洞来源:
Microsoft Security… -
漏洞简介
Microsoft Windows是一款商业视窗操作系统。
Microsoft Windows Shell启动应用程序存在安全问题,远程攻击者可以利用这个漏洞以用户进程权限在机器上执行任意代码。
攻击者可以构建恶意WEB页,诱使用户点击来触发此漏洞,不过需要用户交互。远程攻击者可以利用这个漏洞以用户进程权限在机器上执行任意代码。
漏洞公告
厂商补丁:
Microsoft
———
Microsoft已经为此发布了一个安全公告(MS04-024)以及相应补丁:
MS04-024:Vulnerability in Windows Shell Could Allow Remote Code Execution (839645)
链接:http://www.microsoft.com/technet/security/bulletin/MS04-024.mspx” target=”_blank”>
http://www.microsoft.com/technet/security/bulletin/MS04-024.mspx
补丁下载:
Microsoft Windows NT? Workstation 4.0 Service Pack 6a
http://www.microsoft.com/downloads/details.aspx?FamilyId=53F0C9C1-D72F-48E8-8F70-B29A70A618E2&displaylang=en” target=”_blank”>
http://www.microsoft.com/downloads/details.aspx?FamilyId=53F0C9C1-D72F-48E8-8F70-B29A70A618E2&displaylang=en
Microsoft Windows NT Server 4.0 Service Pack 6a
http://www.microsoft.com/downloads/details.aspx?FamilyId=58906E66-064C-4358-9BF9-BC67B1F57BC5&displaylang=en” target=”_blank”>
http://www.microsoft.com/downloads/details.aspx?FamilyId=58906E66-064C-4358-9BF9-BC67B1F57BC5&displaylang=en
Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack 6
http://www.microsoft.com/downloads/details.aspx?FamilyId=34035CE3-1998-4693-8330-C4515A13407D&displaylang=en” target=”_blank”>
http://www.microsoft.com/downloads/details.aspx?FamilyId=34035CE3-1998-4693-8330-C4515A13407D&displaylang=en
Microsoft Windows NT? Workstation 4.0 Service Pack 6a and NT Server 4.0 Service Pack 6a with Active Desktop
http://www.microsoft.com/downloads/details.aspx?FamilyId=87096271-9716-4a46-93f3-d41fcbdf989a&displaylang=en” target=”_blank”>
http://www.microsoft.com/downloads/details.aspx?FamilyId=87096271-9716-4a46-93f3-d41fcbdf989a&displaylang=en
Microsoft Windows 2000 Service Pack 2, Microsoft Windows 2000 Service Pack 3, Microsoft Windows 2000 Service Pack 4
http://www.microsoft.com/downloads/details.aspx?FamilyId=397BE12B-A026-41A6-8E98-B4027BC6A110&displaylang=en” target=”_blank”>
http://www.microsoft.com/downloads/details.aspx?FamilyId=397BE12B-A026-41A6-8E98-B4027BC6A110&displaylang=en
Microsoft Windows XP and Microsoft Windows XP Service Pack 1
http://www.microsoft.com/downloads/details.aspx?FamilyId=C3365B8E-666B-4C82-A9ED-FC0F84F107BA&displaylang=en” target=”_blank”>
http://www.microsoft.com/downloads/details.aspx?FamilyId=C3365B8E-666B-4C82-A9ED-FC0F84F107BA&displaylang=en
Microsoft Windows XP 64-Bit Edition Service Pack 1
http://www.microsoft.com/downloads/details.aspx?FamilyId=3FEE07F5-9E31-481E-9F89-2549F51147AF&displaylang=en” target=”_blank”>
http://www.microsoft.com/downloads/details.aspx?FamilyId=3FEE07F5-9E31-481E-9F89-2549F51147AF&displaylang=en
Microsoft Windows XP 64-Bit Edition Version 2003
http://www.microsoft.com/downloads/details.aspx?FamilyId=79CCA663-5B72-4345-A3EE-404B466731BC&displaylang=en” target=”_blank”>
http://www.microsoft.com/downloads/details.aspx?FamilyId=79CCA663-5B72-4345-A3EE-404B466731BC&displaylang=en
Microsoft Windows Server? 2003
http://www.microsoft.com/downloads/details.aspx?FamilyId=41C7BB26-3500-4492-A447-33440C404E4F&displaylang=en” target=”_blank”>
http://www.microsoft.com/downloads/details.aspx?FamilyId=41C7BB26-3500-4492-A447-33440C404E4F&displaylang=en
Microsoft Windows Server 2003 64-Bit Edition
http://www.microsoft.com/downloads/details.aspx?FamilyId=79CCA663-5B72-4345-A3EE-404B466731BC&displaylang=en” target=”_blank”>
http://www.microsoft.com/downloads/details.aspx?FamilyId=79CCA663-5B72-4345-A3EE-404B466731BC&displaylang=en
参考网址
来源:US-CERT Technical Alert: TA04-196A
名称: TA04-196A
链接:http://www.us-cert.gov/cas/techalerts/TA04-196A.html
来源:US-CERT Vulnerability Note: VU#106324
名称: VU#106324
链接:http://www.kb.cert.org/vuls/id/106324
来源: BID
名称: 9510
链接:http://www.securityfocus.com/bid/9510
来源: BUGTRAQ
名称: 20040127 GOOROO CROSSING: File Spoofing Internet Explorer 6
链接:http://www.securityfocus.com/archive/1/351379
来源: BUGTRAQ
名称: 20040127 RE: GOOROO CROSSING: File Spoofing Internet Explorer 6
链接:http://www.security-express.com/archives/bugtraq/2004-01/0300.html
来源: MS
名称: MS04-024
链接:http://www.microsoft.com/technet/security/bulletin/ms04-024.asp
来源: XF
名称: ie-clsid-file-extension-spoofing(14964)
链接:http://xforce.iss.net/xforce/xfdb/14964
来源: SECUNIA
名称: 10736
链接:http://secunia.com/advisories/10736/
来源: US Government Resource: oval:org.mitre.oval:def:3604
名称: oval:org.mitre.oval:def:3604
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3604
来源: US Government Resource: oval:org.mitre.oval:def:3533
名称: oval:org.mitre.oval:def:3533
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3533
来源: US Government Resource: oval:org.mitre.oval:def:3386
名称: oval:org.mitre.oval:def:3386
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3386
来源: US Government Resource: oval:org.mitre.oval:def:2894
名称: oval:org.mitre.oval:def:2894
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2894
来源: US Government Resource: oval:org.mitre.oval:def:2381
名称: oval:org.mitre.oval:def:2381
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2381
来源: US Government Resource: oval:org.mitre.oval:def:2245
名称: oval:org.mitre.oval:def:2245
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2245