Trend Micro Security

Internet Explorer Insecure Library Loading Vulnerability (CVE-2011-2019)

  危険度: : 緊急
  CVE識別番号: CVE-2011-2019,MS11-099

  概要

Untrusted search path vulnerability in Microsoft Internet Explorer 9 on Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains an HTML file, aka "Internet Explorer Insecure Library Loading Vulnerability." nvd: Per: http://technet.microsoft.com/en-us/security/bulletin/ms11-099 'FAQ for Internet Explorer Insecure Library Loading Vulnerability - CVE-2011-2019 What is the scope of the vulnerability? This is a remote code execution vulnerability. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights.' Per: http://cwe.mitre.org/data/definitions/426.html

  トレンドマイクロの対策

Apply associated Trend Micro DPI Rules.

  対応方法

  Trend Micro Deep Security DPI Rule Number: 1004878
  Trend Micro Deep Security DPI Rule Name: 1004878 - Internet Explorer Insecure Library Loading Vulnerability Over Network Share (CVE-2011-2019)

  影響を受けるソフトウェア

  • microsoft ie 9