Ãë¾àÁ¡ID |
26490 |
À§Çèµµ |
40 |
Æ÷Æ® |
139,445 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SMB |
»ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛ¿¡´Â ¡®ActiveX ų(Kill) ºñÆ® ´©Àû º¸¾È ¾÷µ¥ÀÌÆ®' ¿¡ ´ëÇÑ hotfix(MS10-008, 978262)°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù. ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â Microsoft ¼ÒÇÁÆ®¿þ¾î¿¡¼ ¹ß°ßµÇ¾î ºñ°ø°³ÀûÀ¸·Î º¸°íµÈ Ãë¾àÁ¡À» ÇØ°áÇÕ´Ï´Ù. ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®ÀÇ ½É°¢µµ´Â Áö¿ø ´ë»óÀÎ ¸ðµç Microsoft Windows 2000 ¹× Windows XP ¹öÀü¿¡ ´ëÇØ ±ä±Þ, Áö¿øµÇ´Â ¸ðµç Windows Vista ¹× Windows 7 ¹öÀü¿¡ ´ëÇØ Áß¿ä, Áö¿ø ´ë»óÀÎ ¸ðµç Windows Server 2003¿¡ ´ëÇØ º¸Åë, ±×¸®°í Áö¿ø ´ë»óÀÎ ¸ðµç Windows Server 2008 ¹× Windows Server 2008 R2¿¡ ´ëÇØ ³·À½ÀÔ´Ï´Ù. ÀÌ Ãë¾àÁ¡À¸·Î ÀÎÇØ »ç¿ëÀÚ°¡ Internet Explorer¸¦ »ç¿ëÇÏ¿© ActiveX ÄÁÆ®·ÑÀ» ÀνºÅϽºÈÇϴ Ư¼öÇÏ°Ô Á¶ÀÛµÈ À¥ ÆäÀÌÁö¸¦ º¼ °æ¿ì ¿ø°Ý ÄÚµå ½ÇÇàÀÌ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù. ½Ã½ºÅÛ¿¡ ´ëÇÑ »ç¿ëÀÚ ±ÇÇÑÀÌ Àû°Ô ±¸¼ºµÈ °èÁ¤ÀÇ »ç¿ëÀÚ´Â °ü¸®ÀÚ ±ÇÇÑÀ¸·Î ÀÛ¾÷ÇÏ´Â »ç¿ëÀÚ¿¡ ºñÇØ ¿µÇâÀ» Àû°Ô ¹Þ½À´Ï´Ù. ¶ÇÇÑ ÀÌ ¾÷µ¥ÀÌÆ®¿¡´Â 4°³ÀÇ Å¸»ç ActiveX ÄÁÆ®·Ñ¿¡ ´ëÇÑ Å³(Kill) ºñÆ®µµ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.microsoft.com/technet/security/bulletin/ms10-008.mspx
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Microsoft Windows 2000 SP4 Microsoft Windows XP SP2,SP3 Microsoft Windows XP (x64) SP2 Microsoft Windows 2003 SP2 Microsoft Windows 2003(x64) SP2 Microsoft Windows Vista SP1,SP2 Microsoft Windows Server 2008 SP2 Microsoft Windows Server 2008(x64) SP2 Microsoft Windows 7 Microsoft Windows 7(x64) Microsoft Windows Server 2008 R2(x64) Microsoft Windows Server 2008 R2 for Itanium-based Systems |
ÇØ°áÃ¥ |
´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° MS10-008¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡(978262)¸¦ Àû¿ëÇÑ´Ù: http://www.microsoft.com/technet/security/bulletin/ms10-008.mspx -- ¶Ç´Â -- Windows Ç÷§ÆûµéÀ» À§ÇÑ ÆÐÄ¡µéÀº ¶ÇÇÑ Microsoft Windows Update À¥ »çÀÌÆ®ÀÎ http://windowsupdate.microsoft.com ¿¡¼µµ ±¸ÇÒ ¼ö ÀÖ´Ù. Windows Update´Â »ç¿ë ÁßÀÎ WindowsÀÇ ¹öÀüÀ» ÀÚµ¿À¸·Î ã¾Æ³»°í ÀûÀýÇÑ ÆÐÄ¡¸¦ Á¦°øÇØ ÁØ´Ù. |
°ü·Ã URL |
CVE-2009-2570,CVE-2009-3735,CVE-2010-0252 (CVE) |
°ü·Ã URL |
34766,38045,38060,38066,38067 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|