Ãë¾àÁ¡ID |
26077 |
À§Çèµµ |
40 |
Æ÷Æ® |
139,445 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMB |
»ó¼¼¼³¸í |
ÇØ´ç È£½ºÆ®¿¡´Â Microsoft RPC/DCOMÀ» À§ÇÑ ´©Àû ¾÷µ¥ÀÌÆ®(KB828741)°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù. ÀÌ ´©Àû º¸¾È ¾÷µ¥ÀÌÆ®´Â ¾Æ·¡¿¡ ¿°ÅµÈ ÀÌÀüÀÇ ¸ðµç RPC/DCOM °ü·Ã ¾÷µ¥ÀÌÆ®µéÀ» Æ÷ÇÔÇϸç, »õ·Ó°Ô ¹ß°ßµÈ ÀϺΠRPC/DCOM °ü·Ã Ãë¾àÁ¡µé¿¡ ´ëÇÑ ÇØ°áÃ¥À» Á¦°øÇÑ´Ù.
* »õ·Î ¹ß°ßµÈ Ãë¾àÁ¡µé: - RPC Runtime Library Ãë¾àÁ¡(CVE-2003-0813): ¿ø°Ý ÄÚµå ½ÇÇà - RPCSS Service Ãë¾àÁ¡(CVE-2004-0116): ¼ºñ½º °ÅºÎ - COM Internet Services(CIS)-RPC over HTTP Ãë¾àÁ¡(CVE-2003-0807): ¼ºñ½º °ÅºÎ - Object Identity Ãë¾àÁ¡(CVE-2004-0124): Á¤º¸ ³ëÃâ
* ÀÌÀüÀÇ º¸¾È ¾÷µ¥ÀÌÆ®µé: - RPC Spoofing DoS Ãë¾àÁ¡: http://www.microsoft.com/technet/security/bulletin/MS98-014.mspx - Malformed RPC Packet DoS Ãë¾àÁ¡ (Q272303) - http://www.microsoft.com/technet/security/bulletin/MS00-066.mspx - RPC endpoint mapper DoS Ãë¾àÁ¡ (Q305399) - http://www.microsoft.com/technet/security/bulletin/MS00-066.mspx - RPC endpoint mapper DoS Ãë¾àÁ¡ (Q331953) - http://www.microsoft.com/technet/security/bulletin/MS03-010.mspx - RPC Interface Code Execution Ãë¾àÁ¡ (KB823980) - http://www.microsoft.com/technet/security/bulletin/MS03-026.mspx - RPCSS Service Code Execution Ãë¾àÁ¡ (KB824146) - http://www.microsoft.com/technet/security/bulletin/MS03-026.mspx
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®ÀÇ ·¹Áö½ºÆ®¸®¸¦ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇØ¼ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.microsoft.com/technet/security/bulletin/MS04-012.mspx
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Microsoft Windows XP, SP1, 64bit Edition SP1, 64bit Edition Version 2003 Microsoft Windows 2000 SP2, SP3, SP4 Microsoft Windows NT Server 4.0 SP6a, Workstation 4.0 SP6a, TSE SP6 Microsoft Windows Server 2003 64bit Edition |
ÇØ°áÃ¥ |
´ÙÀ½ Microsoft Security Bulletin MS04-012¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://www.microsoft.com/technet/security/bulletin/MS04-012.mspx
-- ȤÀº --
À©µµ¿ìÁî Ç÷§ÆûµéÀ» À§ÇÑ ÆÐÄ¡µéÀº ¶ÇÇÑ Microsoft Windows Update À¥ »çÀÌÆ®ÀÎ http://windowsupdate.microsoft.com ¿¡¼µµ ±¸ÇÒ ¼ö ÀÖ´Ù. Windows Update´Â »ç¿ëÁßÀÎ À©µµ¿ìÁîÀÇ ¹öÀüÀ» ÀÚµ¿À¸·Î ã¾Æ³»°í ÀûÀýÇÑ ÆÐÄ¡¸¦ Á¦°øÇØ ÁØ´Ù. |
°ü·Ã URL |
CVE-2003-0813,CVE-2003-0807,CVE-2004-0116,CVE-2004-0124 (CVE) |
°ü·Ã URL |
8811,10123,10127,10121 (SecurityFocus) |
°ü·Ã URL |
13426,15709,15708,15711,15811 (ISS) |
|