Korean
<< Back
VID 26172
Severity 40
Port 139,445
Protocol TCP
Class SMB
Detailed Description The Hotfix (MS05-038, KB896727) for the 'August. 2005 Cumulative Patch for Internet Explorer' has not been applied. This patch replaces the one that is provided in Microsoft Security Bulletin MS05-025(KB883939), which is itself a cumulative update and resolves newly discovered public vulnerability:

1) JPEG Image Rendering Memory Corruption Vulnerability (CAN-2005-1988): Remote Code Execution
2) Web Folder Behaviors Cross-Domain Vulnerability (CAN-2005-1989): Information Disclosure
3) COM Object Instantiation Memory Corruption Vulnerability (CAN-2005-1990): Remote Code Execution

If a user is logged on with administrative privileges, an attacker who successfully exploited the most severe of these vulnerabilities could take complete control of an affected system, including installing programs; viewing, changing, or deleting data; or creating new accounts with full privileges. Users whose accounts are configured to have fewer privileges on the system would be at less risk than users who operate with administrative privileges.

* References:
http://www.microsoft.com/technet/security/bulletin/ms05-038.mspx

* Platforms Affected:
Internet Explorer 5.01 SP3 on Windows 2000 SP3
Internet Explorer 5.01 SP4 on Windows 2000 SP4
Internet Explorer 5.5 SP2 on Microsoft Windows ME
Internet Explorer 6 SP1 on Microsoft Windows 2000 SP4, Windows XP SP1
Internet Explorer 6 SP1 on Microsoft Windows 98, ME
Internet Explorer 6 for Windows XP SP1 (64-Bit Edition)
Internet Explorer 6 for Windows XP 64-Bit Edition Version 2003
Internet Explorer 6 for Windows XP SP2
Internet Explorer 6 for Windows Server 2003
Internet Explorer 6 for Windows Server 2003 64-Bit Edition
Recommendation Apply the appropriate patch (KB896727) for your system, as listed in Microsoft Security Bulletin MS05-038 at http://www.microsoft.com/technet/security/bulletin/ms05-038.mspx

-- OR --

Patches for Windows platforms are also available from the Microsoft Windows Update Web site, http://windowsupdate.microsoft.com . Windows Update detects what version of Windows you are running and offers the appropriate patch.
Related URL CVE-2005-2087 (CVE)
Related URL 14087 (SecurityFocus)
Related URL 21193 (ISS)