漏洞信息详情
多款Microsoft产品SMTP组件和Exchange Routing Engine组件输入验证错误漏洞
漏洞简介
多款Microsoft产品中的SMTP组件和Exchange Routing Engine组件存在输入验证错误漏洞。远程攻击者可借助恶意的DNS响应消息利用该漏洞执行任意代码。以下产品及版本受到影响:Microsoft Windows XP(64-bit)(SMTP),Windows Server 2003(SMTP),Windows Server 2003(64-bit)(SMTP),Exchange Server 2003(Exchange Routing Engine)。
漏洞公告
目前厂商已发布升级补丁以修复漏洞,补丁获取链接:
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-035
参考网址
来源:OVAL
链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2300
来源:XF
链接:https://exchange.xforce.ibmcloud.com/vulnerabilities/17621
来源:XF
链接:https://exchange.xforce.ibmcloud.com/vulnerabilities/17660
来源:BID
链接:https://www.securityfocus.com/bid/11374
来源:MS
链接:https://docs.microsoft.com/en-us/security-updates/securitybulletins/2004/ms04-035
来源:OVAL
链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A3460
来源:OVAL
链接:https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5509
来源:CERT-VN
链接:http://www.kb.cert.org/vuls/id/394792
受影响实体
- Microsoft Exchange_server:2003<!--2000-1-1-->
- Microsoft Windows_2003_server:64-Bit<!--2000-1-1-->
- Microsoft Windows_2003_server:R2<!--2000-1-1-->
- Microsoft Windows_xp:64-Bit<!--2000-1-1-->
补丁
- 多款Microsoft产品SMTP组件和Exchange Routing Engine组件输入验证错误漏洞的修复措施<!--2004-10-12-->
还没有评论,来说两句吧...