xfocus logo xfocus title
首页 焦点原创 安全文摘 安全工具 安全漏洞 焦点项目 焦点论坛 关于我们
English Version

Microsoft Internet Explorer BR549.DLL ActiveX控件缓冲区溢出漏洞


发布时间:2003-08-20
更新时间:2003-08-26
严重程度:
威胁程度:本地管理员权限
错误类型:边界检查错误
利用方式:客户机模式

BUGTRAQ ID:8454
CVE(CAN) ID:CAN-2003-0530

受影响系统
Microsoft Internet Explorer 5.0.1 SP3                              
Microsoft Internet Explorer 5.0.1 SP2                              
   -Microsoft Windows 2000 Advanced Server                        
   -Microsoft Windows 2000 Advanced Server SP1                    
   -Microsoft Windows 2000 Advanced Server SP2                    
   -Microsoft Windows 2000 Datacenter Server                      
   -Microsoft Windows 2000 Datacenter Server SP1                  
   -Microsoft Windows 2000 Datacenter Server SP2                  
   -Microsoft Windows 2000 Professional                            
   -Microsoft Windows 2000 Professional SP1                        
   -Microsoft Windows 2000 Professional SP2                        
   -Microsoft Windows 2000 Server                                  
   -Microsoft Windows 2000 Server SP1                              
   -Microsoft Windows 2000 Server SP2                              
   -Microsoft Windows 2000 Terminal Services                      
   -Microsoft Windows 2000 Terminal Services SP1                  
   -Microsoft Windows 2000 Terminal Services SP2                  
   -Microsoft Windows 95                                          
   -Microsoft Windows 98                                          
   -Microsoft Windows NT Enterprise Server 4.0                    
   -Microsoft Windows NT Enterprise Server 4.0 SP1                
   -Microsoft Windows NT Enterprise Server 4.0 SP2                
   -Microsoft Windows NT Enterprise Server 4.0 SP3                
   -Microsoft Windows NT Enterprise Server 4.0 SP4                
   -Microsoft Windows NT Enterprise Server 4.0 SP5                
   -Microsoft Windows NT Enterprise Server 4.0 SP6                
   -Microsoft Windows NT Enterprise Server 4.0 SP6a                
   -Microsoft Windows NT Server 4.0                                
   -Microsoft Windows NT Server 4.0 SP1                            
   -Microsoft Windows NT Server 4.0 SP2                            
   -Microsoft Windows NT Server 4.0 SP3                            
   -Microsoft Windows NT Server 4.0 SP4                            
   -Microsoft Windows NT Server 4.0 SP5                            
   -Microsoft Windows NT Server 4.0 SP6                            
   -Microsoft Windows NT Server 4.0 SP6a                          
   -Microsoft Windows NT Terminal Server 4.0                      
   -Microsoft Windows NT Terminal Server 4.0 SP1                  
   -Microsoft Windows NT Terminal Server 4.0 SP2                  
   -Microsoft Windows NT Terminal Server 4.0 SP3                  
   -Microsoft Windows NT Terminal Server 4.0 SP4                  
   -Microsoft Windows NT Terminal Server 4.0 SP5                  
   -Microsoft Windows NT Terminal Server 4.0 SP6                  
   -Microsoft Windows NT Terminal Server 4.0 SP6a                  
   -Microsoft Windows NT Workstation 4.0                          
   -Microsoft Windows NT Workstation 4.0 SP1                      
   -Microsoft Windows NT Workstation 4.0 SP2                      
   -Microsoft Windows NT Workstation 4.0 SP3                      
   -Microsoft Windows NT Workstation 4.0 SP4                      
   -Microsoft Windows NT Workstation 4.0 SP5                      
   -Microsoft Windows NT Workstation 4.0 SP6                      
   -Microsoft Windows NT Workstation 4.0 SP6a                      
Microsoft Internet Explorer 5.0.1 SP1                              
   -Microsoft Windows 2000 Advanced Server                        
   -Microsoft Windows 2000 Advanced Server SP1                    
   -Microsoft Windows 2000 Advanced Server SP2                    
   -Microsoft Windows 2000 Datacenter Server                      
   -Microsoft Windows 2000 Datacenter Server SP1                  
   -Microsoft Windows 2000 Datacenter Server SP2                  
   -Microsoft Windows 2000 Professional                            
   -Microsoft Windows 2000 Professional SP1                        
   -Microsoft Windows 2000 Professional SP2                        
   -Microsoft Windows 2000 Server                                  
   -Microsoft Windows 2000 Server SP1                              
   -Microsoft Windows 2000 Server SP2                              
   -Microsoft Windows 2000 Terminal Services                      
   -Microsoft Windows 2000 Terminal Services SP1                  
   -Microsoft Windows 2000 Terminal Services SP2                  
   -Microsoft Windows 95                                          
   -Microsoft Windows 98                                          
   -Microsoft Windows NT Enterprise Server 4.0                    
   -Microsoft Windows NT Enterprise Server 4.0 SP1                
   -Microsoft Windows NT Enterprise Server 4.0 SP2                
   -Microsoft Windows NT Enterprise Server 4.0 SP3                
   -Microsoft Windows NT Enterprise Server 4.0 SP4                
   -Microsoft Windows NT Enterprise Server 4.0 SP5                
   -Microsoft Windows NT Enterprise Server 4.0 SP6                
   -Microsoft Windows NT Enterprise Server 4.0 SP6a                
   -Microsoft Windows NT Server 4.0                                
   -Microsoft Windows NT Server 4.0 SP1                            
   -Microsoft Windows NT Server 4.0 SP2                            
   -Microsoft Windows NT Server 4.0 SP3                            
   -Microsoft Windows NT Server 4.0 SP4                            
   -Microsoft Windows NT Server 4.0 SP5                            
   -Microsoft Windows NT Server 4.0 SP6                            
   -Microsoft Windows NT Server 4.0 SP6a                          
   -Microsoft Windows NT Terminal Server 4.0                      
   -Microsoft Windows NT Terminal Server 4.0 SP1                  
   -Microsoft Windows NT Terminal Server 4.0 SP2                  
   -Microsoft Windows NT Terminal Server 4.0 SP3                  
   -Microsoft Windows NT Terminal Server 4.0 SP4                  
   -Microsoft Windows NT Terminal Server 4.0 SP5                  
   -Microsoft Windows NT Terminal Server 4.0 SP6                  
   -Microsoft Windows NT Terminal Server 4.0 SP6a                  
   -Microsoft Windows NT Workstation 4.0                          
   -Microsoft Windows NT Workstation 4.0 SP1                      
   -Microsoft Windows NT Workstation 4.0 SP2                      
   -Microsoft Windows NT Workstation 4.0 SP3                      
   -Microsoft Windows NT Workstation 4.0 SP4                      
   -Microsoft Windows NT Workstation 4.0 SP5                      
   -Microsoft Windows NT Workstation 4.0 SP6                      
   -Microsoft Windows NT Workstation 4.0 SP6a                      
Microsoft Internet Explorer 5.0.1                                  
   -Microsoft Windows 2000 Advanced Server                        
   -Microsoft Windows 2000 Advanced Server SP1                    
   -Microsoft Windows 2000 Advanced Server SP2                    
   -Microsoft Windows 2000 Datacenter Server                      
   -Microsoft Windows 2000 Datacenter Server SP1                  
   -Microsoft Windows 2000 Datacenter Server SP2                  
   -Microsoft Windows 2000 Professional                            
   -Microsoft Windows 2000 Professional SP1                        
   -Microsoft Windows 2000 Professional SP2                        
   -Microsoft Windows 2000 Server                                  
   -Microsoft Windows 2000 Server SP1                              
   -Microsoft Windows 2000 Server SP2                              
   -Microsoft Windows 2000 Terminal Services                      
   -Microsoft Windows 2000 Terminal Services SP1                  
   -Microsoft Windows 2000 Terminal Services SP2                  
   -Microsoft Windows 95                                          
   -Microsoft Windows 98                                          
   -Microsoft Windows 98SE                                        
   -Microsoft Windows NT Enterprise Server 4.0 SP3                
   -Microsoft Windows NT Enterprise Server 4.0 SP4                
   -Microsoft Windows NT Enterprise Server 4.0 SP5                
   -Microsoft Windows NT Enterprise Server 4.0 SP6                
   -Microsoft Windows NT Enterprise Server 4.0 SP6a                
   -Microsoft Windows NT Server 4.0 SP3                            
   -Microsoft Windows NT Server 4.0 SP4                            
   -Microsoft Windows NT Server 4.0 SP5                            
   -Microsoft Windows NT Server 4.0 SP6                            
   -Microsoft Windows NT Server 4.0 SP6a                          
   -Microsoft Windows NT Terminal Server 4.0 SP3                  
   -Microsoft Windows NT Terminal Server 4.0 SP4                  
   -Microsoft Windows NT Terminal Server 4.0 SP5                  
   -Microsoft Windows NT Terminal Server 4.0 SP6                  
   -Microsoft Windows NT Terminal Server 4.0 SP6a                  
   -Microsoft Windows NT Workstation 4.0 SP3                      
   -Microsoft Windows NT Workstation 4.0 SP4                      
   -Microsoft Windows NT Workstation 4.0 SP5                      
   -Microsoft Windows NT Workstation 4.0 SP6                      
   -Microsoft Windows NT Workstation 4.0 SP6a                      
Microsoft Internet Explorer 5.5 SP2                                
   -Microsoft Windows 2000 Advanced Server                        
   -Microsoft Windows 2000 Advanced Server SP1                    
   -Microsoft Windows 2000 Advanced Server SP2                    
   -Microsoft Windows 2000 Datacenter Server                      
   -Microsoft Windows 2000 Datacenter Server SP1                  
   -Microsoft Windows 2000 Datacenter Server SP2                  
   -Microsoft Windows 2000 Professional                            
   -Microsoft Windows 2000 Professional SP1                        
   -Microsoft Windows 2000 Professional SP2                        
   -Microsoft Windows 2000 Server                                  
   -Microsoft Windows 2000 Server SP1                              
   -Microsoft Windows 2000 Server SP2                              
   -Microsoft Windows 2000 Terminal Services                      
   -Microsoft Windows 2000 Terminal Services SP1                  
   -Microsoft Windows 2000 Terminal Services SP2                  
   -Microsoft Windows 95                                          
   -Microsoft Windows 98                                          
   -Microsoft Windows 98SE                                        
   -Microsoft Windows ME                                          
   -Microsoft Windows NT Enterprise Server 4.0                    
   -Microsoft Windows NT Enterprise Server 4.0 SP1                
   -Microsoft Windows NT Enterprise Server 4.0 SP2                
   -Microsoft Windows NT Enterprise Server 4.0 SP3                
   -Microsoft Windows NT Enterprise Server 4.0 SP4                
   -Microsoft Windows NT Enterprise Server 4.0 SP5                
   -Microsoft Windows NT Enterprise Server 4.0 SP6                
   -Microsoft Windows NT Enterprise Server 4.0 SP6a                
   -Microsoft Windows NT Server 4.0                                
   -Microsoft Windows NT Server 4.0 SP1                            
   -Microsoft Windows NT Server 4.0 SP2                            
   -Microsoft Windows NT Server 4.0 SP3                            
   -Microsoft Windows NT Server 4.0 SP4                            
   -Microsoft Windows NT Server 4.0 SP5                            
   -Microsoft Windows NT Server 4.0 SP6                            
   -Microsoft Windows NT Server 4.0 SP6a                          
   -Microsoft Windows NT Terminal Server 4.0                      
   -Microsoft Windows NT Terminal Server 4.0 SP1                  
   -Microsoft Windows NT Terminal Server 4.0 SP2                  
   -Microsoft Windows NT Terminal Server 4.0 SP3                  
   -Microsoft Windows NT Terminal Server 4.0 SP4                  
   -Microsoft Windows NT Terminal Server 4.0 SP5                  
   -Microsoft Windows NT Terminal Server 4.0 SP6                  
   -Microsoft Windows NT Terminal Server 4.0 SP6a                  
   -Microsoft Windows NT Workstation 4.0                          
   -Microsoft Windows NT Workstation 4.0 SP1                      
   -Microsoft Windows NT Workstation 4.0 SP2                      
   -Microsoft Windows NT Workstation 4.0 SP3                      
   -Microsoft Windows NT Workstation 4.0 SP4                      
   -Microsoft Windows NT Workstation 4.0 SP5                      
   -Microsoft Windows NT Workstation 4.0 SP6                      
   -Microsoft Windows NT Workstation 4.0 SP6a                      
Microsoft Internet Explorer 5.5 SP1                                
   -Microsoft Windows 2000 Advanced Server                        
   -Microsoft Windows 2000 Advanced Server SP1                    
   -Microsoft Windows 2000 Advanced Server SP2                    
   -Microsoft Windows 2000 Datacenter Server                      
   -Microsoft Windows 2000 Datacenter Server SP1                  
   -Microsoft Windows 2000 Datacenter Server SP2                  
   -Microsoft Windows 2000 Professional                            
   -Microsoft Windows 2000 Professional SP1                        
   -Microsoft Windows 2000 Professional SP2                        
   -Microsoft Windows 2000 Server                                  
   -Microsoft Windows 2000 Server SP1                              
   -Microsoft Windows 2000 Server SP2                              
   -Microsoft Windows 2000 Terminal Services                      
   -Microsoft Windows 2000 Terminal Services SP1                  
   -Microsoft Windows 2000 Terminal Services SP2                  
   -Microsoft Windows 95                                          
   -Microsoft Windows 98                                          
   -Microsoft Windows NT Enterprise Server 4.0                    
   -Microsoft Windows NT Enterprise Server 4.0 SP1                
   -Microsoft Windows NT Enterprise Server 4.0 SP2                
   -Microsoft Windows NT Enterprise Server 4.0 SP3                
   -Microsoft Windows NT Enterprise Server 4.0 SP4                
   -Microsoft Windows NT Enterprise Server 4.0 SP5                
   -Microsoft Windows NT Enterprise Server 4.0 SP6                
   -Microsoft Windows NT Enterprise Server 4.0 SP6a                
   -Microsoft Windows NT Server 4.0                                
   -Microsoft Windows NT Server 4.0 SP1                            
   -Microsoft Windows NT Server 4.0 SP2                            
   -Microsoft Windows NT Server 4.0 SP3                            
   -Microsoft Windows NT Server 4.0 SP4                            
   -Microsoft Windows NT Server 4.0 SP5                            
   -Microsoft Windows NT Server 4.0 SP6                            
   -Microsoft Windows NT Server 4.0 SP6a                          
   -Microsoft Windows NT Terminal Server 4.0                      
   -Microsoft Windows NT Terminal Server 4.0 SP1                  
   -Microsoft Windows NT Terminal Server 4.0 SP2                  
   -Microsoft Windows NT Terminal Server 4.0 SP3                  
   -Microsoft Windows NT Terminal Server 4.0 SP4                  
   -Microsoft Windows NT Terminal Server 4.0 SP5                  
   -Microsoft Windows NT Terminal Server 4.0 SP6                  
   -Microsoft Windows NT Terminal Server 4.0 SP6a                  
   -Microsoft Windows NT Workstation 4.0                          
   -Microsoft Windows NT Workstation 4.0 SP1                      
   -Microsoft Windows NT Workstation 4.0 SP2                      
   -Microsoft Windows NT Workstation 4.0 SP3                      
   -Microsoft Windows NT Workstation 4.0 SP4                      
   -Microsoft Windows NT Workstation 4.0 SP5                      
   -Microsoft Windows NT Workstation 4.0 SP6                      
   -Microsoft Windows NT Workstation 4.0 SP6a                      
Microsoft Internet Explorer 5.5                                    
   -Microsoft Windows 2000 Advanced Server                        
   -Microsoft Windows 2000 Advanced Server SP1                    
   -Microsoft Windows 2000 Advanced Server SP2                    
   -Microsoft Windows 2000 Datacenter Server                      
   -Microsoft Windows 2000 Datacenter Server SP1                  
   -Microsoft Windows 2000 Datacenter Server SP2                  
   -Microsoft Windows 2000 Professional                            
   -Microsoft Windows 2000 Professional SP1                        
   -Microsoft Windows 2000 Professional SP2                        
   -Microsoft Windows 2000 Server                                  
   -Microsoft Windows 2000 Server SP1                              
   -Microsoft Windows 2000 Server SP2                              
   -Microsoft Windows 2000 Terminal Services                      
   -Microsoft Windows 2000 Terminal Services SP1                  
   -Microsoft Windows 2000 Terminal Services SP2                  
   -Microsoft Windows 95                                          
   -Microsoft Windows 98                                          
   +Microsoft Windows ME                                          
   -Microsoft Windows NT Enterprise Server 4.0                    
   -Microsoft Windows NT Enterprise Server 4.0 SP1                
   -Microsoft Windows NT Enterprise Server 4.0 SP2                
   -Microsoft Windows NT Enterprise Server 4.0 SP3                
   -Microsoft Windows NT Enterprise Server 4.0 SP4                
   -Microsoft Windows NT Enterprise Server 4.0 SP5                
   -Microsoft Windows NT Enterprise Server 4.0 SP6                
   -Microsoft Windows NT Enterprise Server 4.0 SP6a                
   -Microsoft Windows NT Server 4.0                                
   -Microsoft Windows NT Server 4.0 SP1                            
   -Microsoft Windows NT Server 4.0 SP2                            
   -Microsoft Windows NT Server 4.0 SP3                            
   -Microsoft Windows NT Server 4.0 SP4                            
   -Microsoft Windows NT Server 4.0 SP5                            
   -Microsoft Windows NT Server 4.0 SP6                            
   -Microsoft Windows NT Server 4.0 SP6a                          
   -Microsoft Windows NT Terminal Server 4.0                      
   -Microsoft Windows NT Terminal Server 4.0 SP1                  
   -Microsoft Windows NT Terminal Server 4.0 SP2                  
   -Microsoft Windows NT Terminal Server 4.0 SP3                  
   -Microsoft Windows NT Terminal Server 4.0 SP4                  
   -Microsoft Windows NT Terminal Server 4.0 SP5                  
   -Microsoft Windows NT Terminal Server 4.0 SP6                  
   -Microsoft Windows NT Terminal Server 4.0 SP6a                  
   -Microsoft Windows NT Workstation 4.0                          
   -Microsoft Windows NT Workstation 4.0 SP1                      
   -Microsoft Windows NT Workstation 4.0 SP2                      
   -Microsoft Windows NT Workstation 4.0 SP3                      
   -Microsoft Windows NT Workstation 4.0 SP4                      
   -Microsoft Windows NT Workstation 4.0 SP5                      
   -Microsoft Windows NT Workstation 4.0 SP6                      
   -Microsoft Windows NT Workstation 4.0 SP6a                      
Microsoft Internet Explorer 6.0 SP1                                
Microsoft Internet Explorer 6.0                                    
   -Microsoft Windows 2000 Advanced Server                        
   -Microsoft Windows 2000 Advanced Server SP1                    
   -Microsoft Windows 2000 Advanced Server SP2                    
   -Microsoft Windows 2000 Datacenter Server                      
   -Microsoft Windows 2000 Datacenter Server SP1                  
   -Microsoft Windows 2000 Datacenter Server SP2                  
   -Microsoft Windows 2000 Professional                            
   -Microsoft Windows 2000 Professional SP1                        
   -Microsoft Windows 2000 Professional SP2                        
   -Microsoft Windows 2000 Server                                  
   -Microsoft Windows 2000 Server SP1                              
   -Microsoft Windows 2000 Server SP2                              
   -Microsoft Windows 2000 Terminal Services                      
   -Microsoft Windows 2000 Terminal Services SP1                  
   -Microsoft Windows 2000 Terminal Services SP2                  
   -Microsoft Windows 98                                          
   -Microsoft Windows 98SE                                        
   -Microsoft Windows ME                                          
   -Microsoft Windows NT Enterprise Server 4.0 SP6a                
   -Microsoft Windows NT Server 4.0 SP6a                          
   -Microsoft Windows NT Terminal Server 4.0 SP6a                  
   -Microsoft Windows NT Workstation 4.0 SP6a                      
   +Microsoft Windows Server 2003 Datacenter Edition              
   +Microsoft Windows Server 2003 Datacenter Edition 64-bit        
   +Microsoft Windows Server 2003 Enterprise Edition              
   +Microsoft Windows Server 2003 Enterprise Edition 64-bit        
   +Microsoft Windows Server 2003 Standard Edition                
   +Microsoft Windows Server 2003 Web Edition
详细描述
Microsoft Internet Explorer BR549.dll ActiveX控件对用户提交的数据没有做充分的边界检查,存在缓冲区溢出漏洞,攻击者可能利用此漏洞以用户运行IE进程的权限执行任意指令。

解决方案
厂商已经提供了补丁:

http://www.microsoft.com/technet/security/bulletin/MS03-032.asp

相关信息
Greg Jones of KPMG UK