|
Microsoft Windows hxvz.dll ActiveX-Komponente Speicherkorruption
|
|
|
|
|
Secunia Advisory:
|
SA29714
|
|
|
Herausgegeben:
|
2008-04-08
|
|
Last Update:
|
2008-04-09
|
|
|
Gefahrenstufe:
|

Sehr kritisch
|
|
Auswirkung:
|
Systemzugriff
|
|
Von Wo:
|
Aus dem Internet
|
|
Lösungsstatus:
|
Hersteller-Patch
|
|
| OS: | Microsoft Windows 2000 Advanced Server Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Professional Microsoft Windows 2000 Server Microsoft Windows Server 2003 Datacenter Edition Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Web Edition Microsoft Windows Server 2008 Microsoft Windows Vista Microsoft Windows XP Home Edition Microsoft Windows XP Professional
|
|
| | CVE reference: | CVE-2008-1086 (Secunia mirror)
|
|
|
Want to know the next time vulnerabilities are fixed in this product? - Companies can be alerted via email and SMS! |
|
|
Beschreibung: Eine Sicherheitslücke wurde in Microsoft Windows gemeldet, die böswillige Personen ausnutzen können, um das System eines Benutzers zu kompromittieren.
Die Sicherheitslücke wird durch einen Fehler in der ActiveX-Komponente hxvz.dll verursacht und kann ausgenutzt werden, um eine Speicherkorruption zu verursachen, falls ein Benutzer z.B. dazu gebracht wird, eine bösartige Website zu besuchen.
Eine erfolgreiche Ausnutzung erlaubt die Ausführung von beliebigem Code.
Do you have this product installed on your home computer? Scan using the free Personal Software Inspector. Check if a vulnerable version is installed on computers in your corporate network, using the Network Software Inspector.
Lösung: Verwenden Sie die Patches.
Windows 2000 SP4 with Internet Explorer 5.01 SP4:
http://www.microsoft.com/downloads/de...=0395451F-B719-4F71-A7B4-403D0C7E8FCC
Windows 2000 SP4 with Internet Explorer 6 SP1:
http://www.microsoft.com/downloads/de...=BA6D3AEB-E35A-47CC-BACE-7BD9D58A9D3F
Windows XP SP2:
http://www.microsoft.com/downloads/de...=9DBF002F-FE53-4CC7-A430-35F45C520D10
Windows XP Professional x64 Edition (optionally with SP2):
http://www.microsoft.com/downloads/de...=01400970-DF68-4DAF-AA39-2FC4F969974C
Windows Server 2003 SP1/SP2:
http://www.microsoft.com/downloads/de...=AD384FEA-53BE-4BE3-8ACB-1CD23A7F5405
Windows Server 2003 x64 Edition (optionally with SP2):
http://www.microsoft.com/downloads/de...=FFC5C893-CB24-4875-B0A7-6D5C7AA4D642
Windows Server 2003 with SP1/SP2 for Itanium-based systems:
http://www.microsoft.com/downloads/de...=94CF78D3-B6C3-41BC-993E-3AF3BE0D70F1
Windows Vista (optionally with SP1):
http://www.microsoft.com/downloads/de...=D7F14001-7F42-4CA0-9193-CDF061179B59
Windows Vista x64 Edition (optionally with SP1):
http://www.microsoft.com/downloads/de...=D33462B6-7391-482D-BABE-FB4CD0BEAA21
Windows Server 2008 for 32-bit Systems:
http://www.microsoft.com/downloads/de...=95691924-2813-4A86-9E11-99D853F8E606
Windows Server 2008 for x64-based Systems:
http://www.microsoft.com/downloads/de...=920AE29B-19D0-4089-AC79-F2DA824A2256
Windows Server 2008 for Itanium-based Systems:
http://www.microsoft.com/downloads/de...=66DF79AC-8364-4922-9688-EBC7EC76D89F
Gemeldet und/oder entdeckt von: Von einer anonymen Person durch iDefense Labs gemeldet.
Änderungen: 2008-04-09: Added link to iDefense Labs.
Original Advisory: MS08-023 (948881)
http://www.microsoft.com/technet/security/Bulletin/MS08-023.mspx
iDefense Labs:
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=680
Erweiterte Lösung: The "Erweiterte Lösung" section is available for Secunia customers only. Request a trial and get access to the Secunia Customer Area and Extended Secunia advisories.
|
|
|
|
|
Please note: The information that this Secunia Advisory is based on comes from a third party unless stated otherwise.
Secunia collects, validates, and verifies all vulnerability reports issued by security research groups, vendors, and others.
|
|
|
|
283 Related Secunia Security Advisories, displaying 10
|
|
|
1. Microsoft Windows Event System Erweiterung von Rechten
|
|
2. Microsoft Windows IPsec Verarbeitung von Richtlinien Preisgabe von Informationen
|
|
3. Microsoft Windows "Color Management System" Pufferüberlauf
|
|
4. Microsoft SQL Server und MSDE Mehrere Sicherheitslücken
|
|
5. Microsoft Windows Explorer gespeicherte Suche Sicherheitslücke
|
|
6. Microsoft Windows DNS-Spoofing Sicherheitslücken
|
|
7. Microsoft Windows Pragmatic General Multicast Denial of Service
|
|
8. Microsoft Windows Active Directory Verarbeitung von LDAP-Anfragen Denial of Service
|
|
9. Microsoft Windows WINS Rechteerweiterung
|
|
10. Microsoft DirectX MJPEG/SAMI Sicherheitslücken
|
Show all related advisories
|
|
|
Send Feedback to Secunia
|
|
If you have new information regarding this Secunia advisory or a product in our database, please send it to us using either our web form or email us at vuln@secunia.com.
Ideas, suggestions, and other feedback are most welcome.
|
|
|
|