Trend Micro Security

MS10-077:.NET Framework の脆弱性により、リモートでコードが実行される (2160841)

  危険度: : 緊急
  CVE識別番号: CVE-2010-3228

  概要

This security update addresses a vulnerability in Microsoft .NET Framework. Once a user views a specially crafted Web page via a Web browser that can run XAML Browser Applications (XBAPs), this could allow remote code execution. Moreover, it could also allow remte code execution on a server system running IIS when an attacker uploads a specially crafted ASP.NET page to that server as well as allow the processing of ASP.NET pages.

** Note: This security update does not affect supported editions of Windows Server 2008 or Windows Server 2008 R2 as indicated, when installed using the Server Core installation option.

  トレンドマイクロの対策

詳しい情報については以下のサイトをご参照ください。

  影響を受けるソフトウェア

  • Windows 7 for x64-based Systems
  • Windows Server 2003 with SP2 for Itanium-based Systems
  • Windows Server 2003 x64 Edition Service Pack 2
  • Windows Server 2008 for Itanium-based Systems
  • Windows Server 2008 for Itanium-based Systems Service Pack 2
  • Windows Server 2008 for x64-based Systems
  • Windows Server 2008 for x64-based Systems Service Pack 2**
  • Windows Server 2008 R2 for Itanium-based Systems
  • Windows Server 2008 R2 for x64-based Systems
  • Windows Vista x64 Edition Service Pack 1
  • Windows Vista x64 Edition Service Pack 2
  • Windows XP Professional x64 Edition Service Pack 2