Korean
<< Back
VID 26723
Severity 30
Port 139,445
Protocol TCP
Class SMB
Detailed Description The Hotfix (MS15-084, 3080129) for 'Vulnerabilities in XML Core Services Could Allow Information Disclosure' has not been applied.
This security update resolves vulnerabilities in Microsoft Windows and Microsoft Office. The vulnerabilities could allow information disclosure by either exposing memory addresses if a user clicks a specially crafted link or by explicitly allowing the use of Secure Sockets Layer (SSL) 2.0. However, in all cases an attacker would have no way to force users to click a specially crafted link. An attacker would have to convince users to click the link, typically by way of an enticement in an email or Instant Messenger message.

Multiple MSXML Information Disclosure Vulnerabilities
Information disclosure vulnerabilities exist when Microsoft XML Core Services (MSXML) explicitly allows the use of Secure Sockets Layer (SSL) 2.0. An attacker who successfully exploited these vulnerabilities could decrypt portions of encrypted network information traffic.

MSXML Information Disclosure Vulnerability - CVE-2015-2440
An information disclosure vulnerability exists when Microsoft XML Core Services (MSXML) exposes memory addresses not intended for public disclosure. An attacker could combine this information disclosure vulnerability to bypass Address Space Layout Randomization (ASLR). An attacker who successfully exploited this vulnerability could potentially read private data. The vulnerability would not allow an attacker to execute code or to elevate user rights directly, but the attacker could use it to obtain information in an attempt to further compromise the affected system.

* Note: This check requires an account with administrative privileges which can log into the host to scan. Absence of this condition will result in the check not being performed and a False Negative for all vulnerable hosts.

* References:
https://technet.microsoft.com/en-us/library/security/ms15-084

* Platforms Affected:
Windows Vista SP2
Windows Vista x64 SP2
Windows Server 2008 SP2
Windows Server 2008 x64 SP2
Windows 7 SP1
Windows 7 x64 SP1
Windows Server 2008 R2 SP1
Windows Server 2008 R2 x64 SP1
Windows 8
Windows 8.1
Windows Server 2012
Windows Server 2012 R2
Recommendation Apply the appropriate patch(3080129) for your system, as listed in Microsoft Security Bulletin MS15-084 at https://technet.microsoft.com/en-us/library/security/ms15-084
-- OR --
Patches for Windows platforms are also available from the Microsoft Windows Update Web site, http://windowsupdate.microsoft.com. Windows Update detects what version of Windows you are running and offers the appropriate patch.
Related URL CVE-2015-2434,CVE-2015-2440,CVE-2015-2471 (CVE)
Related URL 76229,76232,76257 (SecurityFocus)
Related URL (ISS)