Trend Micro Security

MS13-058:Windows Defender の脆弱性により、特権が昇格される (2847927)

  危険度: :
  CVE識別番号: CVE-2013-3154

  概要

This security update resolves a privately reported vulnerability in Windows Defender for Windows 7 and Windows Defender when installed on Windows Server 2008 R2. The vulnerability could allow elevation of privilege due to the pathnames used by Windows Defender. An attacker who successfully exploited this vulnerability could execute arbitrary code and take complete control of an affected system. The attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. An attacker must have valid logon credentials to exploit this vulnerability. The vulnerability could not be exploited by anonymous users.

  トレンドマイクロの対策

詳しい情報については以下のサイトをご参照ください。

  対応方法

  影響を受けるソフトウェア

  • Windows 7 for 32-bit Systems Service Pack 1
  • Windows 7 for x64-based Systems Service Pack 1
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1