Microsoft ActiveX Authenticode验证绕过漏洞发布时间:2003-10-15 更新时间:2003-10-15 严重程度:中 威胁程度:其它 错误类型:意外情况处置错误 利用方式:客户机模式 BUGTRAQ ID:8830 CVE(CAN) ID:CAN-2003-0660 受影响系统 Microsoft Windows 2000 Advanced Server SP4详细描述 在部分条件下,Authenticode验证可被绕过,Authenticode是用于在安装和执行控件时进行验证的程序。 要利用这个漏洞,攻击者可以构造恶意页面,诱骗用户访问,然后可使控件在不进行任何提示的情况下安装和执行。目前没有详细信息。 解决方案 补丁下载: Microsoft Windows 2000 Advanced Server SP4: Microsoft Patch Security Update for Microsoft Windows 2000 (KB823182) http://www.microsoft.com/downloads/details.aspx?FamilyId=90D27AEC-7D2A-45FD-B85A-E98E574338F1&displaylang=en Microsoft Windows 2000 Professional SP4: Microsoft Patch Security Update for Microsoft Windows 2000 (KB823182) http://www.microsoft.com/downloads/details.aspx?FamilyId=90D27AEC-7D2A-45FD-B85A-E98E574338F1&displaylang=en Microsoft Windows 2000 Server SP4: Microsoft Patch Security Update for Microsoft Windows 2000 (KB823182) http://www.microsoft.com/downloads/details.aspx?FamilyId=90D27AEC-7D2A-45FD-B85A-E98E574338F1&displaylang=en Microsoft Windows 2000 Professional SP3: Microsoft Patch Security Update for Microsoft Windows 2000 (KB823182) http://www.microsoft.com/downloads/details.aspx?FamilyId=90D27AEC-7D2A-45FD-B85A-E98E574338F1&displaylang=en Microsoft Windows 2000 Server SP3: Microsoft Patch Security Update for Microsoft Windows 2000 (KB823182) http://www.microsoft.com/downloads/details.aspx?FamilyId=90D27AEC-7D2A-45FD-B85A-E98E574338F1&displaylang=en Microsoft Windows 2000 Advanced Server SP3: Microsoft Patch Security Update for Microsoft Windows 2000 (KB823182) http://www.microsoft.com/downloads/details.aspx?FamilyId=90D27AEC-7D2A-45FD-B85A-E98E574338F1&displaylang=en Microsoft Windows 2000 Advanced Server SP2: Microsoft Patch Security Update for Microsoft Windows 2000 Service Pack 2: KB823182 http://www.microsoft.com/downloads/details.aspx?FamilyId=C862E049-58B2-4486-8D98-23183D7EE17D&displaylang=en Microsoft Windows 2000 Professional SP2: Microsoft Patch Security Update for Microsoft Windows 2000 Service Pack 2: KB823182 http://www.microsoft.com/downloads/details.aspx?FamilyId=C862E049-58B2-4486-8D98-23183D7EE17D&displaylang=en Microsoft Windows 2000 Server SP2: Microsoft Patch Security Update for Microsoft Windows 2000 Service Pack 2: KB823182 http://www.microsoft.com/downloads/details.aspx?FamilyId=C862E049-58B2-4486-8D98-23183D7EE17D&displaylang=en Microsoft Windows XP Home SP1: Microsoft Patch Security Update for Microsoft Windows XP (KB823182) http://www.microsoft.com/downloads/details.aspx?FamilyId=6CDF5303-D767-4D68-9BA7-055E93E87847&displaylang=en Microsoft Windows XP Professional SP1: Microsoft Patch Security Update for Microsoft Windows XP (KB823182) http://www.microsoft.com/downloads/details.aspx?FamilyId=6CDF5303-D767-4D68-9BA7-055E93E87847&displaylang=en Microsoft Windows XP 64-bit Edition SP1: Microsoft Patch Security Update for Microsoft Windows XP 64-bit Edition (KB823182) http://www.microsoft.com/downloads/details.aspx?FamilyId=D92EF2E8-C03A-43C0-B428-D76C4B669151&displaylang=en Microsoft Windows Server 2003 Standard Edition : Microsoft Patch Security Update for Microsoft Windows Server 2003 (KB823182) http://www.microsoft.com/downloads/details.aspx?FamilyId=135D8C00-7B4B-4C21-8EAA-D58814635E0D&displaylang=en Microsoft Windows Server 2003 Enterprise Edition : Microsoft Patch Security Update for Microsoft Windows Server 2003 (KB823182) http://www.microsoft.com/downloads/details.aspx?FamilyId=135D8C00-7B4B-4C21-8EAA-D58814635E0D&displaylang=en Microsoft Windows Server 2003 Web Edition : Microsoft Patch Security Update for Microsoft Windows Server 2003 (KB823182) http://www.microsoft.com/downloads/details.aspx?FamilyId=135D8C00-7B4B-4C21-8EAA-D58814635E0D&displaylang=en Microsoft Windows Server 2003 Enterprise Edition 64-bit : Microsoft Patch Security Update for Microsoft Windows Server 2003 64-bit Edition (KB823182) http://www.microsoft.com/downloads/details.aspx?FamilyId=4DFF5AAB-FA62-4B81-9C08-5C9FCB905E11&displaylang=en Microsoft Windows XP 64-bit Edition Version 2003 : Microsoft Patch Security Update for Microsoft Windows Server 2003 64-bit Edition (KB823182) http://www.microsoft.com/downloads/details.aspx?FamilyId=4DFF5AAB-FA62-4B81-9C08-5C9FCB905E11&displaylang=en Microsoft Windows XP Professional : Microsoft Patch Security Update for Microsoft Windows XP (KB823182) http://www.microsoft.com/downloads/details.aspx?FamilyId=6CDF5303-D767-4D68-9BA7-055E93E87847&displaylang=en Microsoft Windows XP Home : Microsoft Patch Security Update for Microsoft Windows XP (KB823182) http://www.microsoft.com/downloads/details.aspx?FamilyId=6CDF5303-D767-4D68-9BA7-055E93E87847&displaylang=en Microsoft Windows XP 64-bit Edition : Microsoft Patch Security Update for Microsoft Windows XP 64-bit Edition (KB823182) http://www.microsoft.com/downloads/details.aspx?FamilyId=D92EF2E8-C03A-43C0-B428-D76C4B669151&displaylang=en Microsoft Windows NT Workstation 4.0 SP6a: Microsoft Patch Security Update for Microsoft NT Workstation 4.0: KB823182 http://www.microsoft.com/downloads/details.aspx?FamilyId=921466F5-BC40-4E8E-BB57-6B81B57C21B6&displaylang=en Microsoft Windows NT Enterprise Server 4.0 SP6a: Microsoft Patch Security Update for Microsoft NT 4.0 Server (KB823182) http://www.microsoft.com/downloads/details.aspx?FamilyId=21F64FF0-9175-42BE-A8E4-BDC59A98BDF2&displaylang=en Microsoft Windows NT Server 4.0 SP6a: Microsoft Patch Security Update for Microsoft NT 4.0 Server (KB823182) http://www.microsoft.com/downloads/details.aspx?FamilyId=21F64FF0-9175-42BE-A8E4-BDC59A98BDF2&displaylang=en Microsoft Windows NT Terminal Server 4.0 SP6: Microsoft Patch Security Update for Microsoft Terminal Server (KB823182) http://www.microsoft.com/downloads/details.aspx?FamilyId=C6688576-4682-4A30-BBD7-1817F2944890&displaylang=en 相关信息 参考:http://www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS03-041.asp |