|
Brought to you by:
Suppliers of:
|
|
|
| |
| The vulnerability could allow remote code execution if an attacker set up a malicious Web page that invokes the Indexing Service through a call to its ActiveX component. This call could include a malicious URL and exploit the vulnerability, granting the attacker access to the client system with the privileges of the user browsing the Web page. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. |
| |
Credit:
The information has been provided by Yamata Li and Microsoft.
The original article can be found at: http://www.microsoft.com/technet/security/bulletin/ms09-057.mspx
|
| |
Vulnerable Systems:
* Microsoft Windows 2000
* Windows XP
* Windows Server 2003
Immune Systems:
* Windows Vista
* Windows Server 2008
* Windows 7
This security update is rated Important for all supported editions of Microsoft Windows 2000, Windows XP, and Windows Server 2003.
The security update addresses the vulnerability by modifying the way that the Indexing Service ActiveX control processes URLs.
Patch Availability:
http://go.microsoft.com/fwlink/?LinkID=40747
CVE Information:
CVE-2009-2507
|
|
|
|
|