漏洞信息详情
Microsoft Internet Explorer 安全漏洞
漏洞简介
Microsoft Internet Explorer(IE)是美国微软(Microsoft)公司的一款Windows操作系统附带的Web浏览器。
Microsoft Internet Explorer存在安全漏洞。远程攻击者可以获取缓存内容的物理位置,并且在Local Computer Zone上打开,然后使用已编译的HTML help (.chm)文件执行任意程序。
漏洞公告
Microsoft has released a patch which rectifies this issue.
http://www.microsoft.com/windows/ie/download/critical/q286045/default.asp
There have been reports that it is possible to exploit this vulnerability through HTML email and news messages on patched systems.
参考网址
来源:MS
链接:https://docs.microsoft.com/en-us/security-updates/securitybulletins/2001/ms01-015
来源:MISC
链接:http://www.guninski.com/chmtempmain.html
来源:OVAL
链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A920
来源:OSVDB
链接:http://www.osvdb.org/7823
来源:BID
链接:https://www.securityfocus.com/bid/2456
来源:XF
链接:https://exchange.xforce.ibmcloud.com/vulnerabilities/5567
受影响实体
- Microsoft Windows_script_host:5.5<!--2000-1-1-->
- Microsoft Windows_script_host:5.1<!--2000-1-1-->
- Microsoft Ie:5.5<!--2000-1-1-->
- Microsoft Ie:5.01<!--2000-1-1-->
补丁
暂无
还没有评论,来说两句吧...