危険度: 緊急
  CVE識別番号: CVE-2011-0029,MS11-017
  情報公開日: 7 21, 2015

  概要

Untrusted search path vulnerability in the client in Microsoft Remote Desktop Connection 5.2, 6.0, 6.1, and 7.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .rdp file, aka "Remote Desktop Insecure Library Loading Vulnerability." nvd: Per: http://cwe.mitre.org/data/definitions/426.html 'CWE-426: Untrusted Search Path'

  トレンドマイクロの対策

Apply associated Trend Micro DPI Rules.

  対応方法

  Trend Micro Deep Security DPI Rule Number: 1004373
  Trend Micro Deep Security DPI Rule Name: 1004373 - Identified Microsoft DLL File Over Network Share

  影響を受けるソフトウェア

  • microsoft remote_desktop_connection_client 5.2
  • microsoft remote_desktop_connection_client 6.0
  • microsoft remote_desktop_connection_client 6.1
  • microsoft remote_desktop_connection_client 7.0
  • microsoft windows_2003_server
  • microsoft windows_7 -
  • microsoft windows_server_2003
  • microsoft windows_server_2008
  • microsoft windows_server_2008 -
  • microsoft windows_server_2008 r2
  • microsoft windows_vista
  • microsoft windows_xp
  • microsoft windows_xp -