| Microsoft Windows Knowledge Base Article 969897 update is not installed (WinMs09kb969897Update) |
|---|
| Vuln ID: | 50776 | |
|---|---|---|
| Risk Level: | High |
WinMs09kb969897Update |
| Platforms: | Microsoft Internet Explorer: 6.0, Microsoft Internet Explorer: 6.0 SP1, Microsoft Windows 2000: SP4, Microsoft Windows XP: SP2, Microsoft Internet Explorer: 7.0, Microsoft Windows Vista, Microsoft Windows Server 2003: SP2, Microsoft Windows Server 2003: SP2 Itanium, Microsoft Windows Server 2003: SP2 x64, Microsoft Windows Vista: x64, Microsoft Windows XP: SP2 x64 Professional, Microsoft Windows Vista: SP1, Microsoft Windows Vista: SP1 x64, Microsoft Internet Explorer: 5.0.1 SP4, Microsoft Internet Explorer: 8.0, Microsoft Windows Server 2008: Itanium, Microsoft Windows Server 2008: x32, Microsoft Windows Server 2008: x64, Microsoft Windows XP: SP3, Microsoft Windows Vista: SP2 x64, Microsoft Windows Vista: SP2, Microsoft Windows Server 2008: SP2 x32, Microsoft Windows Server 2008: SP2 x64, Microsoft Windows Server 2008: SP2 Itanium | |
| Description: | Microsoft Knowledge Base Article 969897 is not installed, which could allow a remote attacker to exploit the following vulnerabilities: Microsoft Internet Explorer could allow a remote attacker to bypass cross-domain security restrictions, caused by a race condition when updating pages across domains. By persuading a victim to visit a specially-crafted Web site, a remote attacker bypass same-origin policy restrictions to gain unauthorized access to other domains and obtain sensitive information from the system. Microsoft Internet Explorer could allow a remote attacker to bypass cross-domain security restrictions, caused by an error when rendering cached content. By persuading a victim to visit a specially-crafted Web site, an attacker could exploit this vulnerability to bypass cross-domain security restrictions and view content from the local computer or another browser window in another domain or Internet Explorer zone. Microsoft Internet Explorer could allow a remote attacker to execute arbitrary code on the system when file and printer sharing is enabled, caused by a memory corruption error when handling DHTML objects. By persuading a victim to visit a specially-crafted Web page that contains certain unexpected method calls to HTML objects, an attacker could exploit this vulnerability to execute arbitrary code with privileges of the victim. Microsoft Internet Explorer could allow a remote attacker to execute arbitrary code on the system when file and printer sharing is enabled, caused by a memory corruption error when handling HTML objects. By persuading a victim to visit a specially-crafted Web page, an attacker could exploit this vulnerability to execute arbitrary code with privileges of the victim. Microsoft Internet Explorer could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption error when handling certain objects. By persuading a victim to visit a specially-crafted Web page that attempts to access an object that has not been initialized or has been deleted, an attacker could exploit this vulnerability to execute arbitrary code with privileges of the victim. Microsoft Internet Explorer could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption error when handling HTML objects that have not been correctly initialized or have been deleted. By persuading a victim to visit a specially-crafted Web page, an attacker could exploit this vulnerability to execute arbitrary code with privileges of the victim. Microsoft Internet Explorer could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption error when handling HTML objects that have not been correctly initialized or have been deleted. By persuading a victim to visit a specially-crafted Web page, an attacker could exploit this vulnerability to execute arbitrary code with privileges of the victim. Microsoft Internet Explorer could allow a remote attacker to execute arbitrary code on the system, caused by a memory corruption error when handling HTML objects that have not been correctly initialized or have been deleted. By persuading a victim to visit a specially-crafted Web page, an attacker could exploit this vulnerability to execute arbitrary code with privileges of the victim. |
|
| Remedy: | Apply the appropriate patch for your system, as listed in Microsoft Security Bulletin MS09-019. See References. |
|
| False Positives: | ||
| False Negatives: | ||
| Required Permission: | Windows login | |
| Additional Information: | ||
| References: | Microsoft Security Bulletin MS09-019 IBM Internet Security Systems X-Force Database IBM Internet Security Systems X-Force Database IBM Internet Security Systems X-Force Database IBM Internet Security Systems X-Force Database IBM Internet Security Systems X-Force Database IBM Internet Security Systems X-Force Database IBM Internet Security Systems X-Force Database IBM Internet Security Systems X-Force Database ISS X-Force CVE CVE-2007-3091 |
|
![]() Know Your Risks |
![]() Common Vulnerabilties & Exposures |