VID |
26172 |
Severity |
40 |
Port |
139,445 |
Protocol |
TCP |
Class |
SMB |
Detailed Description |
The Hotfix (MS05-038, KB896727) for the 'August. 2005 Cumulative Patch for Internet Explorer' has not been applied. This patch replaces the one that is provided in Microsoft Security Bulletin MS05-025(KB883939), which is itself a cumulative update and resolves newly discovered public vulnerability:
1) JPEG Image Rendering Memory Corruption Vulnerability (CAN-2005-1988): Remote Code Execution 2) Web Folder Behaviors Cross-Domain Vulnerability (CAN-2005-1989): Information Disclosure 3) COM Object Instantiation Memory Corruption Vulnerability (CAN-2005-1990): Remote Code Execution
If a user is logged on with administrative privileges, an attacker who successfully exploited the most severe of these vulnerabilities could take complete control of an affected system, including installing programs; viewing, changing, or deleting data; or creating new accounts with full privileges. Users whose accounts are configured to have fewer privileges on the system would be at less risk than users who operate with administrative privileges.
* References: http://www.microsoft.com/technet/security/bulletin/ms05-038.mspx
* Platforms Affected: Internet Explorer 5.01 SP3 on Windows 2000 SP3 Internet Explorer 5.01 SP4 on Windows 2000 SP4 Internet Explorer 5.5 SP2 on Microsoft Windows ME Internet Explorer 6 SP1 on Microsoft Windows 2000 SP4, Windows XP SP1 Internet Explorer 6 SP1 on Microsoft Windows 98, ME Internet Explorer 6 for Windows XP SP1 (64-Bit Edition) Internet Explorer 6 for Windows XP 64-Bit Edition Version 2003 Internet Explorer 6 for Windows XP SP2 Internet Explorer 6 for Windows Server 2003 Internet Explorer 6 for Windows Server 2003 64-Bit Edition |
Recommendation |
Apply the appropriate patch (KB896727) for your system, as listed in Microsoft Security Bulletin MS05-038 at http://www.microsoft.com/technet/security/bulletin/ms05-038.mspx
-- OR --
Patches for Windows platforms are also available from the Microsoft Windows Update Web site, http://windowsupdate.microsoft.com . Windows Update detects what version of Windows you are running and offers the appropriate patch. |
Related URL |
CVE-2005-2087 (CVE) |
Related URL |
14087 (SecurityFocus) |
Related URL |
21193 (ISS) |
|