PT-2014-1059 · Microsoft · Vbscript+1
Publicado
2014-02-11
·
Atualizado
2018-10-12
·
CVE-2014-0271
CVSS v2.0
9.3
Alta
| Vetor | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Internet Explorer versions 6 through 11
VBScript versions 5.6 through 5.8
Description
The issue is related to the handling of objects in memory by the VBScript engine, allowing remote attackers to execute arbitrary code or cause memory corruption via a crafted web site. This could enable an attacker to gain control over an affected system, especially if the current user has administrative rights, potentially leading to the installation of programs, modification or deletion of data, and creation of new accounts with full user rights.
Recommendations
For Internet Explorer versions 6 through 11, update to a version that includes the fix for this issue.
For VBScript versions 5.6 through 5.8, consider disabling the VBScript engine until a patch is available.
As a temporary workaround, restrict access to web sites that could potentially exploit this vulnerability.
Avoid using Internet Explorer or VBScript for sensitive operations until the issue is resolved.
Correção
RCE
DoS
Buffer Overflow
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Internet Explorer
Vbscript