English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 26490
À§Çèµµ 40
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡´Â ¡®ActiveX ų(Kill) ºñÆ® ´©Àû º¸¾È ¾÷µ¥ÀÌÆ®' ¿¡ ´ëÇÑ hotfix(MS10-008, 978262)°¡ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù.
ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®´Â Microsoft ¼ÒÇÁÆ®¿þ¾î¿¡¼­ ¹ß°ßµÇ¾î ºñ°ø°³ÀûÀ¸·Î º¸°íµÈ Ãë¾àÁ¡À» ÇØ°áÇÕ´Ï´Ù. ÀÌ º¸¾È ¾÷µ¥ÀÌÆ®ÀÇ ½É°¢µµ´Â Áö¿ø ´ë»óÀÎ ¸ðµç Microsoft Windows 2000 ¹× Windows XP ¹öÀü¿¡ ´ëÇØ ±ä±Þ, Áö¿øµÇ´Â ¸ðµç Windows Vista ¹× Windows 7 ¹öÀü¿¡ ´ëÇØ Áß¿ä, Áö¿ø ´ë»óÀÎ ¸ðµç Windows Server 2003¿¡ ´ëÇØ º¸Åë, ±×¸®°í Áö¿ø ´ë»óÀÎ ¸ðµç Windows Server 2008 ¹× Windows Server 2008 R2¿¡ ´ëÇØ ³·À½ÀÔ´Ï´Ù. ÀÌ Ãë¾àÁ¡À¸·Î ÀÎÇØ »ç¿ëÀÚ°¡ Internet Explorer¸¦ »ç¿ëÇÏ¿© ActiveX ÄÁÆ®·ÑÀ» ÀνºÅϽºÈ­Çϴ Ư¼öÇÏ°Ô Á¶ÀÛµÈ À¥ ÆäÀÌÁö¸¦ º¼ °æ¿ì ¿ø°Ý ÄÚµå ½ÇÇàÀÌ ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù. ½Ã½ºÅÛ¿¡ ´ëÇÑ »ç¿ëÀÚ ±ÇÇÑÀÌ Àû°Ô ±¸¼ºµÈ °èÁ¤ÀÇ »ç¿ëÀÚ´Â °ü¸®ÀÚ ±ÇÇÑÀ¸·Î ÀÛ¾÷ÇÏ´Â »ç¿ëÀÚ¿¡ ºñÇØ ¿µÇâÀ» Àû°Ô ¹Þ½À´Ï´Ù. ¶ÇÇÑ ÀÌ ¾÷µ¥ÀÌÆ®¿¡´Â 4°³ÀÇ Å¸»ç ActiveX ÄÁÆ®·Ñ¿¡ ´ëÇÑ Å³(Kill) ºñÆ®µµ Æ÷ÇԵǾî ÀÖ½À´Ï´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ È£½ºÆ®·Î ·Î±×ÀÎ ÇÒ ¼ö ÀÖ´Â °ü¸®ÀÚ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇؼ­ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.microsoft.com/technet/security/bulletin/ms10-008.mspx

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Windows 2000 SP4
Microsoft Windows XP SP2,SP3
Microsoft Windows XP (x64) SP2
Microsoft Windows 2003 SP2
Microsoft Windows 2003(x64) SP2
Microsoft Windows Vista SP1,SP2
Microsoft Windows Server 2008 SP2
Microsoft Windows Server 2008(x64) SP2
Microsoft Windows 7
Microsoft Windows 7(x64)
Microsoft Windows Server 2008 R2(x64)
Microsoft Windows Server 2008 R2 for Itanium-based Systems
ÇØ°áÃ¥ ´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½Ã¹° MS10-008¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ´ëÇÑ ÀûÀýÇÑ ÆÐÄ¡(978262)¸¦ Àû¿ëÇÑ´Ù:
http://www.microsoft.com/technet/security/bulletin/ms10-008.mspx
-- ¶Ç´Â --
Windows Ç÷§ÆûµéÀ» À§ÇÑ ÆÐÄ¡µéÀº ¶ÇÇÑ Microsoft Windows Update À¥ »çÀÌÆ®ÀÎ http://windowsupdate.microsoft.com ¿¡¼­µµ ±¸ÇÒ ¼ö ÀÖ´Ù. Windows Update´Â »ç¿ë ÁßÀÎ WindowsÀÇ ¹öÀüÀ» ÀÚµ¿À¸·Î ã¾Æ³»°í ÀûÀýÇÑ ÆÐÄ¡¸¦ Á¦°øÇØ ÁØ´Ù.
°ü·Ã URL CVE-2009-2570,CVE-2009-3735,CVE-2010-0252 (CVE)
°ü·Ã URL 34766,38045,38060,38066,38067 (SecurityFocus)
°ü·Ã URL (ISS)