Gravité: : Élevé
  Identifiant(s) CVE: : CVE-2011-0031,MS11-009
  Date du conseil: 21 juillet 2015

  Description

The (1) JScript 5.8 and (2) VBScript 5.8 scripting engines in Microsoft Windows Server 2008 R2 and Windows 7 do not properly load decoded scripts obtained from web pages, which allows remote attackers to trigger memory corruption and consequently obtain sensitive information via a crafted web site, aka "Scripting Engines Information Disclosure Vulnerability."

  Information Exposure Rating:

Apply associated Trend Micro DPI Rules.

  Solutions

  Trend Micro Deep Security DPI Rule Number: 1004588
  Trend Micro Deep Security DPI Rule Name: 1004588 - Microsoft Script Encoder Memory Corruption Vulnerability

  Affected software and version:

  • Microsoft Windows Server 2008 R2
  • Microsoft Windows 7