Búsqueda de    
Vulnerabilidad   
    Buscar 324607 Descripciones CVE y
146377 Descripciones de Pruebas,
accesos 10,000+ referencias cruzadas.
Pruebas   CVE   Todos  

ID de Prueba:1.3.6.1.4.1.25623.1.0.801399
Categoría:Windows
Título:Microsoft Windows Insecure Library Loading Remote Code Execution Vulnerabilities (2269637)
Resumen:This host is prone to Remote Code Execution vulnerabilities.
Descripción:Summary:
This host is prone to Remote Code Execution vulnerabilities.

Vulnerability Insight:
The flaws are due to:

- An error in the loading of dynamic link libraries (DLLs). If an application
does not securely load DLL files, an attacker may be able to cause the
application to load an arbitrary library.

- A specific insecure programming practices that allow so-called
'binary planting' or 'DLL preloading attacks', which allows the attacker to
execute arbitrary code in the context of the user running the vulnerable
application when the user opens a file from an untrusted location.

Vulnerability Impact:
Successful exploitation will allow attackers to execute arbitrary code or to
elevate privileges.

Affected Software/OS:
- Microsoft Windows 7

- Microsoft Windows XP Service Pack 3 and prior

- Microsoft Windows 2003 Service Pack 2 and prior

- Microsoft Windows Vista Service Pack 2 and prior

- Microsoft Windows Server 2008 Service Pack 2 and prior

Solution:
The vendor has released updates. Please see the references for more information.

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

CopyrightCopyright (C) 2010 Greenbone AG

Esta es sólo una de 146377 pruebas de vulnerabilidad en nuestra serie de pruebas. Encuentre más sobre cómo ejecutar una auditoría de seguridad completa.

Para ejecutar una prueba gratuita de esta vulnerabilidad contra su sistema, regístrese ahora.




© 1998-2025 E-Soft Inc. Todos los derechos reservados.