万卷书   首页 > 电脑书籍 > 病毒档案 >IE的任意代码执行漏洞
 

影响系统:

  Microsoft Internet Explorer 6.0SP1
   Microsoft Internet Explorer 5.5SP2
   Microsoft Internet Explorer 5.5SP1
  Microsoft Internet Explorer 5.5
   Microsoft Internet Explorer 6.0
     - Microsoft Windows NT 4.0 SP6a
     - Microsoft Windows 98 SE
     - Microsoft Windows 98
     - Microsoft Windows 2003 Web Edition
     - Microsoft Windows 2003 Standard Edition
     - Microsoft Windows 2003 Enterprise Edition 64-bit
     - Microsoft Windows 2003 Enterprise Edition
     - Microsoft Windows 2003 Datacenter Edition 64-bit
     - Microsoft Windows 2003 Datacenter Edition
     - Microsoft Windows 2000 Server SP2
     - Microsoft Windows 2000 Server SP1
     - Microsoft Windows 2000 Server
     - Microsoft Windows 2000 Professional SP2
     - Microsoft Windows 2000 Professional SP1
     - Microsoft Windows 2000 Professional
     - Microsoft Windows 2000 Datacenter Server SP2
     - Microsoft Windows 2000 Datacenter Server SP1
     - Microsoft Windows 2000 Datacenter Server
     - Microsoft Windows 2000 Advanced Server SP2
     - Microsoft Windows 2000 Advanced Server SP1
     - Microsoft Windows 2000 Advanced Server

详细描述:

  Microsoft Internet Explorer是一款流行的WEB浏览程序。Microsoft Internet Explorer在处理包含嵌入可执行文件的页面时存在问题,远程攻击者可以利用这个漏洞构建恶意页面,诱使用户访问,导致任意命令被执行。问题是使用Adodb.Stream对象写本地文件到本地系统,通过构建包含恶意脚本和可执行文件的自执行HTML文件,可导致包含的恶意代码被执行。

  目前厂商尚未提供补丁程序。