Microsoft Internet Explorer 'winhlp32.exe' 'MsgBox()' Remote Code Execution Vulnerability
2011年2月15日
风险等级: 中(zhōng)
CVE标识符: : CVE-2010-0483
建议日期 : 2010年3月2日
描述
Microsoft Internet Explorer does not properly validate parameters passed to the MsgBox function. This vulnerability could allow an attacker to host a maliciously crafted web page and run arbitrary code if they could convince a user to visit the web page and then get them to press the F1 key in response to a pop up dialog box.
保护信息
Apply associated Trend Micro DPI rules.
解决方案
Trend Micro Deep Security DPI Rule Number: 1004019
Trend Micro Deep Security DPI Rule Name: 1004019 - Microsoft Internet Explorer win32hlp Remote Code Execution
受感染软件和版本:
- Microsoft Internet Explorer