Internet Explorer Insecure Library Loading Vulnerability (CVE-2011-2019)
Schweregrad:: Kritisch
CVE Kennungen:: CVE-2011-2019,MS11-099
Hinweisdatum: 21 Juli 2015
Beschreibung
Untrusted search path vulnerability in Microsoft Internet Explorer 9 on Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an HTML file, aka "Internet Explorer Insecure Library Loading Vulnerability."
nvd: Per: http://technet.microsoft.com/en-us/security/bulletin/ms11-099
'FAQ for Internet Explorer Insecure Library Loading Vulnerability - CVE-2011-2019
What is the scope of the vulnerability?
This is a remote code execution vulnerability. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.'
Per: http://cwe.mitre.org/data/definitions/426.html
Trend Micro Lösungen
Apply associated Trend Micro DPI Rules.
Lösungen
Trend Micro Deep Security DPI Rule Number: 1004878
Trend Micro Deep Security DPI Rule Name: 1004878 - Internet Explorer Insecure Library Loading Vulnerability Over Network Share (CVE-2011-2019)
Betroffene Software und Version:
- microsoft ie 9