(MS10-097) Insecure Library Loading in Internet Connection Signup Wizard Could Allow Remote Code Execution (2443105)
Publish date: 10 de febrero de 2011
Gravedad: High
Identificadores de CVE : CVE-2010-3144
Fecha recomendada: 10 de febrero de 2011
Descripci¨®n
This update resolves a vulnerability in the Internet Connection Signup Wizard of Microsoft Windows, which could allow remote code execution. This exploit works if a user opens an .ins or .isp file located in the same network folder as a specially crafted library file. More specifically, this update addresses the vulnerability by correcting the manner by which the Internet Connection Signup Wizard loads external libraries.
Revelaci¨®n de la informaci¨®n
For information on patches specific to the affected software, please proceed to the .
Soluciones
Parche :
Software y versi¨®n afectados
- Windows XP Service Pack 3
- Windows XP Professional x64 Edition Service Pack 2
- Windows Server 2003 Service Pack 2
- Windows Server 2003 x64 Edition Service Pack 2
- Windows Server 2003 with SP2 for Itanium-based Systems