(MS11-001) Vulnerability in Windows Backup Manager Could Allow Remote Code Execution (2478935)
Data de publicação: 10 fevereiro 2011
Schweregrad: : Alto
Identificador(es) CVE: : CVE-2010-3145
Data do informe: 10 fevereiro 2011
Descrição
This security update resolves a vulnerability in Windows Backup Manager, which could allow remote code execution. The exploit works when a user�opens a legitimate Windows Backup Manager file located in the same directory as a specially crafted library file.�If the said user�visits an untrusted remote file system location or WebDAV share,�it could cause the Windows Backup Manager to load the specially crafted library file. More specifically, this security update addresses the vulnerability by correcting the manner by which Windows Backup Manager loads external libraries.
Exposição das informações
For information on patches specific to the affected software, please proceed to the Microsoft Web page.
Software infectado e versão:
- Windows Vista Service Pack 1 and Windows Vista Service Pack 2
- Windows Vista x64 Edition Service Pack 1 and Windows Vista x64 Edition Service Pack 2