Gravità: : Alto
  Identificatori CVE: CVE-2010-3144
  Data notifica: 10 febbraio 2011

  Descrizione

This update resolves a vulnerability in the Internet Connection Signup Wizard of Microsoft Windows, which could allow remote code execution. This exploit works if a user opens an .ins or .isp file located in the same network folder as a specially crafted library file. More specifically, this update addresses the vulnerability by correcting the manner by which the Internet Connection Signup Wizard loads external libraries.

  Informazioni esposizione:

For information on patches specific to the affected software, please proceed to the Microsoft Web page.

  Soluzioni

  Software e versione interessati:

  • Windows XP Service Pack 3
  • Windows XP Professional x64 Edition Service Pack 2
  • Windows Server 2003 Service Pack 2
  • Windows Server 2003 x64 Edition Service Pack 2
  • Windows Server 2003 with SP2 for Itanium-based Systems