Gravité: : Critique
  CVE Identifier: CVE-2011-1257,CVE-2011-1960,CVE-2011-1961,CVE-2011-1962,CVE-2011-1963,CVE-2011-1964,CVE-2011-2383
  Date du conseil: 24 août 2011

  Description

This security update resolves five privately reported vulnerabilities and two publicly disclosed vulnerabilities in Internet Explorer. Severe vulnerabilities could allow remote code execution if a user views a specially crafted Web page using Internet Explorer. An attacker who successfully exploits any of these vulnerabilities could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

  Information Exposure Rating:

Trend Micro Deep Security shields networks through Deep Packet Inspection (DPI) rules. Trend Micro customers using OfficeScan with Intrusion Defense Firewall (IDF) plugin are also protected from attacks using these vulnerabilities. Please refer to the filter number and filter name when applying appropriate DPI and/or IDF rules.

  Solutions

  Patch: : http://www.microsoft.com/technet/security/bulletin/MS11-057.mspx

  Trend Micro Deep Security DPI Rule Number: 1004758
  Trend Micro Deep Security DPI Rule Name: Microsoft Internet Explorer Window Open Race Condition Vulnerability (CVE-2011-1257)

  Affected software and version:

  • Internet Explorer 6 (Windows XP Service Pack 3)
  • Internet Explorer 6 (Windows XP Professional x64 Edition Service Pack 2)
  • Internet Explorer 6 (Windows Server 2003 Service Pack 2)
  • Internet Explorer 6 (Windows Server 2003 x64 Edition Service Pack 2)
  • Internet Explorer 6 (Windows Server 2003 with SP2 for Itanium-based Systems)
  • Internet Explorer 7 (Windows XP Service Pack 3)
  • Internet Explorer 7 (Windows XP Professional x64 Edition Service Pack 2)
  • Internet Explorer 7 (Windows Server 2003 Service Pack 2)
  • Internet Explorer 7 (Windows Server 2003 x64 Edition Service Pack 2)
  • Internet Explorer 7 (Windows Server 2003 with SP2 for Itanium-based Systems)
  • Internet Explorer 7 (Windows Vista Service Pack 2)
  • Internet Explorer 7 (Windows Vista x64 Edition Service Pack 2)
  • Internet Explorer 7 (Windows Server 2008 for 32-bit Systems Service Pack 2)
  • Internet Explorer 7 (Windows Server 2008 for x64-based Systems Service Pack 2)
  • Internet Explorer 7 (Windows Server 2008 for Itanium-based Systems Service Pack 2)
  • Internet Explorer 8 (Windows XP Service Pack 3)
  • Internet Explorer 8 (Windows XP Professional x64 Edition Service Pack 2)
  • Internet Explorer 8 (Windows Server 2003 Service Pack 2)
  • Internet Explorer 8 (Windows Server 2003 x64 Edition Service Pack 2)
  • Internet Explorer 8 (Windows Vista Service Pack 2)
  • Internet Explorer 8 (Windows Vista x64 Edition Service Pack 2)
  • Internet Explorer 8 (Windows Server 2008 for 32-bit Systems Service Pack 2)
  • Internet Explorer 8 (Windows Server 2008 for x64-based Systems Service Pack 2)
  • Internet Explorer 8 (Windows 7 for 32-bit Systems and Windows 7 for 32-bit Systems Service Pack 1)
  • Internet Explorer 8 (Windows 7 for x64-based Systems and Windows 7 for x64-based Systems Service Pack 1)
  • Internet Explorer 8 (Windows Server 2008 R2 for x64-based Systems and Windows Server 2008 R2 for x64-based Systems Service Pack 1)
  • Internet Explorer 8 (Windows Server 2008 R2 for Itanium-based Systems and Windows Server 2008 R2 for Itanium-based Systems Service Pack 1)
  • Internet Explorer 9 (Windows Vista Service Pack 2)
  • Internet Explorer 9 (Windows Vista x64 Edition Service Pack 2)
  • Internet Explorer 9 (Windows Server 2008 for 32-bit Systems Service Pack 2)
  • Internet Explorer 9 (Windows Server 2008 for x64-based Systems Service Pack 2)
  • Internet Explorer 9 (Windows 7 for 32-bit Systems and Windows 7 for 32-bit Systems Service Pack 1)
  • Internet Explorer 9 (Windows 7 for x64-based Systems and Windows 7 for x64-based Systems Service Pack 1)
  • Internet Explorer 9 (Windows Server 2008 R2 for x64-based Systems and Windows Server 2008 R2 for x64-based Systems Service Pack 1)