Vulnerability   
Search   
    Search 324607 CVE descriptions
and 146377 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.900281
Category:Windows : Microsoft Bulletins
Title:Microsoft IE Developer Tools WMITools and Windows Messenger ActiveX Control Vulnerability (2508272)
Summary:This host is missing a critical security update according to; Microsoft Bulletin MS11-027.
Description:Summary:
This host is missing a critical security update according to
Microsoft Bulletin MS11-027.

Vulnerability Insight:
An unspecified error exists in the IE Developer Tools(iedvtool.dll), WMITools
(WBEMSingleView.OCX) and Windows Messenger (msgsc.dll) ActiveX Controls when
used with Internet Explorer. Attackers can execute arbitrary code by tricking
a user into visiting a specially crafted web page.

Vulnerability Impact:
Successful exploitation will allow remote attackers to execute arbitrary
code.

Affected Software/OS:
- Microsoft Windows 7 Service Pack 1 and prior

- Microsoft Windows XP Service Pack 3 and prior

- Microsoft Windows 2K3 Service Pack 2 and prior

- Microsoft Windows Vista Service Pack 1/2 and prior

- Microsoft Windows Server 2008 Service Pack 1/2 and prior

Solution:
The vendor has released updates. Please see the references for more information.

As a workaround set the killbit for the following CLSIDs:

{1a6fe369-f28c-4ad9-a3e6-2bcb50807cf1}, {2745E5F5-D234-11D0-847A-00C04FD7BB08},
{FB7199AB-79BF-11d2-8D94-0000F875C541}

CVSS Score:
9.3

CVSS Vector:
AV:N/AC:M/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2010-0811
Cert/CC Advisory: TA10-159B
http://www.us-cert.gov/cas/techalerts/TA10-159B.html
Microsoft Security Bulletin: MS10-034
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2010/ms10-034
Microsoft Security Bulletin: MS11-027
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2011/ms11-027
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12534
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A7492
Common Vulnerability Exposure (CVE) ID: CVE-2010-3973
BugTraq ID: 45546
http://www.securityfocus.com/bid/45546
CERT/CC vulnerability note: VU#725596
http://www.kb.cert.org/vuls/id/725596
http://www.exploit-db.com/exploits/15809
http://blogs.technet.com/b/srd/archive/2011/01/07/assessing-the-risk-of-public-issues-currently-being-tracked-by-the-msrc.aspx
http://www.wooyun.org/bug.php?action=view&id=1006
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12475
http://secunia.com/advisories/42693
http://www.vupen.com/english/advisories/2010/3301
XForce ISS Database: ms-wmi-wbemsingleview-ce(64250)
https://exchange.xforce.ibmcloud.com/vulnerabilities/64250
Common Vulnerability Exposure (CVE) ID: CVE-2011-1243
BugTraq ID: 47197
http://www.securityfocus.com/bid/47197
http://osvdb.org/71788
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A12524
http://secunia.com/advisories/44159
Common Vulnerability Exposure (CVE) ID: CVE-2010-4588
http://twitter.com/carsteneiram/status/17526155733110784
CopyrightCopyright (C) 2011 Greenbone AG

This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.