Windows Shell远程任意代码执行漏洞(MS04-024)

漏洞信息详情

Windows Shell远程任意代码执行漏洞(MS04-024)

漏洞简介

Microsoft Windows是一款商业视窗操作系统。
Microsoft Windows Shell启动应用程序存在安全问题,远程攻击者可以利用这个漏洞以用户进程权限在机器上执行任意代码。
攻击者可以构建恶意WEB页,诱使用户点击来触发此漏洞,不过需要用户交互。远程攻击者可以利用这个漏洞以用户进程权限在机器上执行任意代码。

漏洞公告

厂商补丁:
Microsoft
———
Microsoft已经为此发布了一个安全公告(MS04-024)以及相应补丁:

MS04-024:Vulnerability in Windows Shell Could Allow Remote Code Execution (839645)

链接:http://www.microsoft.com/technet/security/bulletin/MS04-024.mspx” target=”_blank”>
http://www.microsoft.com/technet/security/bulletin/MS04-024.mspx

补丁下载:

Microsoft Windows NT? Workstation 4.0 Service Pack 6a

http://www.microsoft.com/downloads/details.aspx?FamilyId=53F0C9C1-D72F-48E8-8F70-B29A70A618E2&displaylang=en” target=”_blank”>
http://www.microsoft.com/downloads/details.aspx?FamilyId=53F0C9C1-D72F-48E8-8F70-B29A70A618E2&displaylang=en

Microsoft Windows NT Server 4.0 Service Pack 6a

http://www.microsoft.com/downloads/details.aspx?FamilyId=58906E66-064C-4358-9BF9-BC67B1F57BC5&displaylang=en” target=”_blank”>
http://www.microsoft.com/downloads/details.aspx?FamilyId=58906E66-064C-4358-9BF9-BC67B1F57BC5&displaylang=en

Microsoft Windows NT Server 4.0 Terminal Server Edition Service Pack 6

http://www.microsoft.com/downloads/details.aspx?FamilyId=34035CE3-1998-4693-8330-C4515A13407D&displaylang=en” target=”_blank”>
http://www.microsoft.com/downloads/details.aspx?FamilyId=34035CE3-1998-4693-8330-C4515A13407D&displaylang=en

Microsoft Windows NT? Workstation 4.0 Service Pack 6a and NT Server 4.0 Service Pack 6a with Active Desktop

http://www.microsoft.com/downloads/details.aspx?FamilyId=87096271-9716-4a46-93f3-d41fcbdf989a&displaylang=en” target=”_blank”>
http://www.microsoft.com/downloads/details.aspx?FamilyId=87096271-9716-4a46-93f3-d41fcbdf989a&displaylang=en

Microsoft Windows 2000 Service Pack 2, Microsoft Windows 2000 Service Pack 3, Microsoft Windows 2000 Service Pack 4

http://www.microsoft.com/downloads/details.aspx?FamilyId=397BE12B-A026-41A6-8E98-B4027BC6A110&displaylang=en” target=”_blank”>
http://www.microsoft.com/downloads/details.aspx?FamilyId=397BE12B-A026-41A6-8E98-B4027BC6A110&displaylang=en

Microsoft Windows XP and Microsoft Windows XP Service Pack 1

http://www.microsoft.com/downloads/details.aspx?FamilyId=C3365B8E-666B-4C82-A9ED-FC0F84F107BA&displaylang=en” target=”_blank”>
http://www.microsoft.com/downloads/details.aspx?FamilyId=C3365B8E-666B-4C82-A9ED-FC0F84F107BA&displaylang=en

Microsoft Windows XP 64-Bit Edition Service Pack 1

http://www.microsoft.com/downloads/details.aspx?FamilyId=3FEE07F5-9E31-481E-9F89-2549F51147AF&displaylang=en” target=”_blank”>
http://www.microsoft.com/downloads/details.aspx?FamilyId=3FEE07F5-9E31-481E-9F89-2549F51147AF&displaylang=en

Microsoft Windows XP 64-Bit Edition Version 2003

http://www.microsoft.com/downloads/details.aspx?FamilyId=79CCA663-5B72-4345-A3EE-404B466731BC&displaylang=en” target=”_blank”>
http://www.microsoft.com/downloads/details.aspx?FamilyId=79CCA663-5B72-4345-A3EE-404B466731BC&displaylang=en

Microsoft Windows Server? 2003

http://www.microsoft.com/downloads/details.aspx?FamilyId=41C7BB26-3500-4492-A447-33440C404E4F&displaylang=en” target=”_blank”>
http://www.microsoft.com/downloads/details.aspx?FamilyId=41C7BB26-3500-4492-A447-33440C404E4F&displaylang=en

Microsoft Windows Server 2003 64-Bit Edition

http://www.microsoft.com/downloads/details.aspx?FamilyId=79CCA663-5B72-4345-A3EE-404B466731BC&displaylang=en” target=”_blank”>
http://www.microsoft.com/downloads/details.aspx?FamilyId=79CCA663-5B72-4345-A3EE-404B466731BC&displaylang=en

参考网址

来源:US-CERT Technical Alert: TA04-196A
名称: TA04-196A
链接:http://www.us-cert.gov/cas/techalerts/TA04-196A.html

来源:US-CERT Vulnerability Note: VU#106324
名称: VU#106324
链接:http://www.kb.cert.org/vuls/id/106324

来源: BID
名称: 9510
链接:http://www.securityfocus.com/bid/9510

来源: BUGTRAQ
名称: 20040127 GOOROO CROSSING: File Spoofing Internet Explorer 6
链接:http://www.securityfocus.com/archive/1/351379

来源: BUGTRAQ
名称: 20040127 RE: GOOROO CROSSING: File Spoofing Internet Explorer 6
链接:http://www.security-express.com/archives/bugtraq/2004-01/0300.html

来源: MS
名称: MS04-024
链接:http://www.microsoft.com/technet/security/bulletin/ms04-024.asp

来源: XF
名称: ie-clsid-file-extension-spoofing(14964)
链接:http://xforce.iss.net/xforce/xfdb/14964

来源: SECUNIA
名称: 10736
链接:http://secunia.com/advisories/10736/

来源: US Government Resource: oval:org.mitre.oval:def:3604
名称: oval:org.mitre.oval:def:3604
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3604

来源: US Government Resource: oval:org.mitre.oval:def:3533
名称: oval:org.mitre.oval:def:3533
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3533

来源: US Government Resource: oval:org.mitre.oval:def:3386
名称: oval:org.mitre.oval:def:3386
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:3386

来源: US Government Resource: oval:org.mitre.oval:def:2894
名称: oval:org.mitre.oval:def:2894
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2894

来源: US Government Resource: oval:org.mitre.oval:def:2381
名称: oval:org.mitre.oval:def:2381
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2381

来源: US Government Resource: oval:org.mitre.oval:def:2245
名称: oval:org.mitre.oval:def:2245
链接:http://oval.mitre.org/repository/data/getDef?id=oval:org.mitre.oval:def:2245

© 版权声明
THE END
喜欢就支持一下吧
点赞0 分享