|
|
|
|
Bonjour,
J'ai fait une analyse avec trend online qui a détécté une faille risquée je ne comprend pas l'anglais est-ce que quelqu'un peut m'aider s'il vous plait à la supprimer?
Home > Security Advisories > (MS06-025) Vulnerability in Routing and Remote Access Could Allow Remote Execution (911280)
(MS06-025) Vulnerability in Routing and Remote Access Could Allow Remote Execution (911280)
Vulnerability Identifier: CVE-2006-2370, CVE-2006-2371
Discovery Date: Jun 13, 2006
Risk: Critical
Vulnerability Assessment Pattern File: 044
Affected Software:
Microsoft Windows 2000 Service Pack 4
Microsoft Windows Server 2003
Microsoft Windows Server 2003 64-Bit Edition
Microsoft Windows Server 2003 for Itanium-based Systems
Microsoft Windows Server 2003 Service Pack 1
Microsoft Windows Server 2003 with SP1 for Itanium-based Systems
Microsoft Windows XP Professional SP1
Microsoft Windows XP Professional SP2
Microsoft Windows XP Professional x64 Edition
Description:
This Microsoft security bulletin resolves the following issues in Routing and Remote Access service:
RRAS Memory Corruption Vulnerability (CVE-2006-2370)
RASMAN Registry Corruption Vulnerability (CVE-2006-2370)
Both vulnerabilities are caused by an unchecked buffer in the Routing and Remote Access service. Once exploited, both vulnerabilities could allow a malicious user or a malware to execute arbitrary code with the privileges of the currently logged-on user. This can enable the malicious user to take complete control of the affected computer.
On Windows XP Service Pack 2 and Windows Server 2003 systems, an attacker must have valid logon credentials and be able to log on locally to exploit these vulnerabilities. In the aforementioned systems, these vulnerabilities could not be exploited remotely by anonymous users or by users who have standard user accounts. However, the affected component is available remotely to users who have administrative permissions.
These vulnerabilities can be exploited by a malicious attacker or a malware on this scenario:
Internet/Network-based attack scenario:
Authenticated users on Windows 2000 and on Windows XP Service Pack 1 can remotely exploit this vulnerability. An anonymous attacker cannot load and run a program remotely by using this vulnerability.
Authenticated users on Windows XP Service Pack 2 and Windows Server 2003 can remotely exploit these vulnerabilities. An anonymous attacker or by users with standard user accounts cannot load and run a program remotely by using these vulnerabilities.
Patch Information:
The Microsoft patch is available at Microsoft Security Bulletin MS06-025.
Workaround Fixes:
The workarounds for this vulnerability are found at Microsoft Security Bulletin MS06-025.
En effet, même si je ne comprends pas tout l'anglais, il y a bien un problème "critique".
|
Bonjour,
|
Re !
|
Répondre à joer
|