VID |
26153 |
Severity |
40 |
Port |
139,445 |
Protocol |
TCP |
Class |
SMB |
Detailed Description |
The Hotfix (MS05-025, KB883939) for the 'Jun. 2005 Cumulative Patch for Internet Explorer' has not been applied. This patch replaces the one that is provided in Microsoft Security Bulletin MS05-020(KB890923), which is itself a cumulative update and resolves newly discovered public vulnerability:
1) PNG Image Rendering Memory Corruption Vulnerability (CAN-2005-1211): Remote Code Execution 2) XML Redirect Information Disclosure Vulnerability (CAN-2002-0648): Information Disclosure
If a user is logged on with administrative privileges, an attacker who successfully exploited the most severe of these vulnerabilities could take complete control of an affected system, including installing programs; viewing, changing, or deleting data; or creating new accounts with full privileges. Users whose accounts are configured to have fewer privileges on the system would be at less risk than users who operate with administrative privileges.
* References: http://www.microsoft.com/technet/security/bulletin/ms05-025.mspx http://xforce.iss.net/xforce/alerts/id/196
* Platforms Affected: Internet Explorer 5.01 SP3 on Windows 2000 SP3 Internet Explorer 5.01 SP4 on Windows 2000 SP4 Internet Explorer 5.5 SP2 on Microsoft Windows ME Internet Explorer 6 SP1 on Microsoft Windows 2000 SP4, Windows XP SP1 Internet Explorer 6 SP1 on Microsoft Windows 98, ME Internet Explorer 6 for Windows XP SP1 (64-Bit Edition) Internet Explorer 6 for Windows XP 64-Bit Edition Version 2003 Internet Explorer 6 for Windows XP SP2 Internet Explorer 6 for Windows Server 2003 Internet Explorer 6 for Windows Server 2003 64-Bit Edition |
Recommendation |
Apply the appropriate patch (KB883939) for your system, as listed in Microsoft Security Bulletin MS05-025 at http://www.microsoft.com/technet/security/bulletin/ms05-025.mspx
-- OR --
Patches for Windows platforms are also available from the Microsoft Windows Update Web site, http://windowsupdate.microsoft.com . Windows Update detects what version of Windows you are running and offers the appropriate patch. |
Related URL |
CVE-2005-1191 (CVE) |
Related URL |
13248 (SecurityFocus) |
Related URL |
20162 (ISS) |
|