Microsoft Windows 2000 TroubleShooter ActiveX控件缓冲区溢出漏洞发布时间:2003-10-15 更新时间:2003-10-15 严重程度:中 威胁程度:普通用户访问权限 错误类型:环境错误 利用方式:客户机模式 BUGTRAQ ID:8833 CVE(CAN) ID:CAN-2003-0662 受影响系统 Microsoft Windows 2000 Advanced Server SP4未影响系统 Microsoft Windows 95详细描述 Microsoft Local Troubleshooter是一个ActiveX控件,使用于Microsoft Windows Troubleshooting help,这个控件默认在W2K系统中安装。 其中一个方法在调用超长字符串时可导致发生缓冲区溢出。当"RunQuery2"在第一个参数中调用超长字符串时会发生溢出。利用恶意页面,可能在用户系统上执行任意指令。 测试代码 ------sample.htm----------- <object id="test" classid="CLSID:4B106874-DD36-11D0-8B44-00A024DD9EFF" > </object> <script> test.RunQuery2("longstringhere","",""); </script> --------------------------- 解决方案 补丁下载: Microsoft Windows 2000 Advanced Server SP4: Microsoft Patch KB826232 http://www.microsoft.com/downloads/details.aspx?FamilyId=FC1FD84B-B3A4-43F5-804B-A2608EC56163&displaylang=en Microsoft Windows 2000 Datacenter Server SP4: Microsoft Patch KB826232 http://www.microsoft.com/downloads/details.aspx?FamilyId=FC1FD84B-B3A4-43F5-804B-A2608EC56163&displaylang=en Microsoft Windows 2000 Professional SP4: Microsoft Patch KB826232 http://www.microsoft.com/downloads/details.aspx?FamilyId=FC1FD84B-B3A4-43F5-804B-A2608EC56163&displaylang=en Microsoft Windows 2000 Server SP4: Microsoft Patch KB826232 http://www.microsoft.com/downloads/details.aspx?FamilyId=FC1FD84B-B3A4-43F5-804B-A2608EC56163&displaylang=en Microsoft Windows 2000 Professional SP3: Microsoft Patch KB826232 http://www.microsoft.com/downloads/details.aspx?FamilyId=FC1FD84B-B3A4-43F5-804B-A2608EC56163&displaylang=en Microsoft Windows 2000 Server SP3: Microsoft Patch KB826232 http://www.microsoft.com/downloads/details.aspx?FamilyId=FC1FD84B-B3A4-43F5-804B-A2608EC56163&displaylang=en Microsoft Windows 2000 Advanced Server SP3: Microsoft Patch KB826232 http://www.microsoft.com/downloads/details.aspx?FamilyId=FC1FD84B-B3A4-43F5-804B-A2608EC56163&displaylang=en Microsoft Windows 2000 Datacenter Server SP3: Microsoft Patch KB826232 http://www.microsoft.com/downloads/details.aspx?FamilyId=FC1FD84B-B3A4-43F5-804B-A2608EC56163&displaylang=en Microsoft Windows 2000 Advanced Server SP2: Microsoft Patch KB826232 http://www.microsoft.com/downloads/details.aspx?FamilyId=48D16574-9B17-463B-A5D2-D75BA5128EF9&displaylang=en Microsoft Windows 2000 Datacenter Server SP2: Microsoft Patch KB826232 http://www.microsoft.com/downloads/details.aspx?FamilyId=48D16574-9B17-463B-A5D2-D75BA5128EF9&displaylang=en Microsoft Windows 2000 Professional SP2: Microsoft Patch KB826232 http://www.microsoft.com/downloads/details.aspx?FamilyId=48D16574-9B17-463B-A5D2-D75BA5128EF9&displaylang=en Microsoft Windows 2000 Server SP2: Microsoft Patch KB826232 http://www.microsoft.com/downloads/details.aspx?FamilyId=48D16574-9B17-463B-A5D2-D75BA5128EF9&displaylang=en 相关信息 Greg Jones and Cesar Cerrudo. 参考:http://www.securityfocus.com/advisories/5979 http://archives.neohapsis.com/archives/fulldisclosure/2003-q4/0965.html http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-042.asp |