安全公告CN-SA04-32A 发布日期:2004-7-14 安全等级:/upload/p1_23xs25.jpg
公开程度:公共
更新说明: 7月14日,CNCERT/CC从多个渠道收到微软发布多个安全公告的消息,消息提醒用户及时进行安全更新。实际上,微软的这些安全公告也已在其网站上发布,共计7个,其中,涉及到的严重漏洞2个、重要漏洞4个、中等漏洞1个,分列如下:
严重 MS04-022 任务计划程序远程执行代码漏洞
严重 MS04-023 HTML帮助远程执行代码漏洞
重要 MS04-019 工具管理器权限提升漏洞
重要 MS04-020 POSIX权限提升漏洞
重要 MS04-021 IIS 4.0缓冲区溢出漏洞
重要 MS04-024 Windows Shell远程执行代码漏洞
中等 MS04-018 Outlook Express拒绝服务漏洞
摘要:
MS04-022:任务计划程序由于其进行应用程序名称验证的方式而存在一个远程执行代码漏洞。 受影响的系统: Windows 2000 Service Pack 2 Windows 2000 Service Pack 3 Windows 2000 Service Pack 4 Windows XP和Windows XP Service Pack 1 Windows XP 64-Bit Edition Service Pack 1 受影响的组件: Internet Explorer 6 安装于Windows NT 4.0 SP6a(Workstation、Server或Terminal Server Edition)
MS04-023:在对特制 showHelp URL 的处理方式中存在一个远程执行代码漏洞。 受影响的系统: Windows 2000 Service Pack 2 Windows 2000 Service Pack 3 Windows 2000 Service Pack 4 Windows XP和Windows XP Service Pack 1 Windows XP 64-Bit Edition Service Pack 1 Windows XP 64-Bit Edition Version 2003 Windows Server 2003 Windows Server 2003 64-Bit Edition 受影响的组件: Internet Explorer 6 安装于Windows NT 4.0 SP6a(Workstation、Server或Terminal Server Edition) 另外,请查看MS04-O23公告中的常见问题解答以了解涉及下列操作系统的相关信息: Microsoft Windows 98 Microsoft Windows 98 Second Edition (SE) Microsoft Windows Millennium Edition (ME)
MS04-019:在工具管理器启动应用程序的方式中存在一个权限提升漏洞。已登录的用户可以强制工具管理器以系统权限启动应用程序。 受影响的系统: Windows 2000 Service Pack 2 Windows 2000 Service Pack 3 Windows 2000 Service Pack 4
MS04-020:POSIX 子系统中存在的权限提升漏洞可能允许登录用户完全控制系统。 受影响的系统: Windows NT Workstation 4.0 Service Pack 6a Windows NT Server 4.0 Service Pack 6a Windows NT Server 4.0 Terminal Server Edition Service Pack 6 Windows 2000 Service Pack 2 Windows 2000 Service Pack 3 Windows 2000 Service Pack 4
MS04-021:Internet Information Server 4.0 中存在一个缓冲区溢出漏洞。 受影响的系统: Windows NT Workstation 4.0 Service Pack 6a Windows NT Server 4.0 Service Pack 6a
MS04-024:在 Windows Shell 启动应用程序的方式中存在一个远程执行代码漏洞。要利用此漏洞,需要进行用户交互。 受影响的系统: Windows NT Workstation 4.0 Service Pack 6a Windows NT Server 4.0 Service Pack 6a Windows NT Server 4.0 Terminal Server Edition Service Pack 6 Windows 2000 Service Pack 2 Windows 2000 Service Pack 3 Windows 2000 Service Pack 4 Windows XP and Windows XP Service Pack 1 Windows XP 64-Bit Edition Service Pack 1 Windows XP 64-Bit Edition Version 2003 Windows Server 2003 Windows Server 2003 64-Bit Edition 另外,请查看MS04-O24公告中的常见问题解答以了解涉及下列操作系统的相关信息: Microsoft Windows 98 Microsoft Windows 98 Second Edition (SE) Microsoft Windows Millennium Edition (ME)
MS04-018:存在的拒绝服务漏洞可能允许攻击者发送特制电子邮件,从而导致 Outlook Express 出现故障。 受影响的系统: Windows NT Workstation 4.0 Service Pack 6a Windows NT Server 4.0 Service Pack 6a Windows NT Server 4.0 Terminal Server Edition Service Pack 6 Windows 2000 Service Pack 2 Windows 2000 Service Pack 3 Windows 2000 Service Pack 4 Windows XP and Windows XP Service Pack 1 Windows XP 64-Bit Edition Service Pack 1 Windows XP 64-Bit Edition Version 2003 Windows Server 2003 Windows Server 2003 64-Bit Edition 另外,请查看MS04-O18中的常见问题解答以了解涉及下列操作系统的相关信息: Microsoft Windows 98 Microsoft Windows 98 Second Edition (SE) Microsoft Windows Millennium Edition (ME)
解决方案: 按照微软公告提示下载并安装更新。