PT-2011-4430 · Microsoft · Windows Xp+3
Publicado
2011-12-13
·
Atualizado
2019-02-26
·
CVE-2011-3397
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows XP versions SP2 through SP3
Microsoft Server 2003 version SP2
Description
A remote code execution issue exists in the Microsoft Time component, allowing attackers to execute arbitrary code via a crafted web site. An attacker could exploit this by constructing a specially crafted Web page, potentially gaining the same user rights as the logged-on user when a user views the page.
Recommendations
For Microsoft Windows XP versions SP2 through SP3, consider restricting access to the Microsoft Time component until a fix is available.
For Microsoft Server 2003 version SP2, avoid using the affected component in Internet Explorer to minimize the risk of exploitation.
Correção
RCE
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Internet Explorer
Server 2003
Windows Xp
Windows