(MS10-071) Cumulative Security Update for Internet Explorer (2360131)

  Severity: CRITICAL
  CVE Identifier: CVE-2010-0808,CVE-2010-3324,CVE-2010-3325,CVE-2010-3326,CVE-2010-3327,CVE-2010-3328,CVE-2010-3329,CVE-2010-3330,CVE-2010-3331
  Advisory Date: FEB 20, 2013

  DESCRIPTION

This security update addresses vulnerabilities in Internet Explorer (IE) that could allow remote code execution once a user views a specially crafted Web page using Internet Explorer. Users with administrative rights are more affected by this vulnerability than those with fewer rights on the system.

  TREND MICRO PROTECTION INFORMATION

For information on patches specific to the affected software, please proceed to the Microsoft Web page.

Trend Micro clients using OfficeScan with Intrusion Defense Firewall (IDF) may refer to the table below for the pattern filter identifier(s):

Vulnerability ID Identifier & Title IDF First Pattern Version IDF First Pattern Release Version
CVE-2010-3324 1004463 - HTML Sanitization Vulnerability 10-032 Oct 13, 2010
CVE-2010-3326 1004474 - Uninitialized Memory Corruption Vulnerability 10-032 Oct 13, 2010
CVE-2010-3328 1004466 - Uninitialized Memory Corruption Vulnerability 10-032 Oct 13, 2010
CVE-2010-3329 1004468 - Uninitialized Memory Corruption Vulnerability 10-032 Oct 13, 2010
CVE-2010-3330 1004476 - Cross-Domain Information Disclosure Vulnerability 10-032 Oct 13, 2010
CVE-2010-3331 1004467 - Uninitialized Memory Corruption Vulnerability 10-032 Oct 13, 2010

  SOLUTION

  AFFECTED SOFTWARE AND VERSION

  • Microsoft Internet Explorer 6 (Windows Server 2003 Service Pack 2)
  • Microsoft Internet Explorer 6 (Windows Server 2003 with SP2 for Itanium-based Systems)
  • Microsoft Internet Explorer 6 (Windows Server 2003 x64 Edition Service Pack 2)
  • Microsoft Internet Explorer 6 (Windows XP Professional x64 Edition Service Pack 2)
  • Microsoft Internet Explorer 6 (Windows XP Service Pack 3)
  • Microsoft Internet Explorer 7 (Microsoft Windows Server 2003 Service Pack 2)
  • Microsoft Internet Explorer 7 (Microsoft Windows Server 2003 with SP2 for Itanium-based Systems)
  • Microsoft Internet Explorer 7 (Microsoft Windows Server 2003 x64 Edition Service Pack 2)
  • Microsoft Internet Explorer 7 (Windows Server 2003 Service Pack 2)
  • Microsoft Internet Explorer 7 (Windows Server 2008 for 32-bit Systems Service Pack 2)
  • Microsoft Internet Explorer 7 (Windows Server 2008 for 32-bit Systems)
  • Microsoft Internet Explorer 7 (Windows Server 2008 for Itanium-based Systems Service Pack 2)
  • Microsoft Internet Explorer 7 (Windows Server 2008 for Itanium-based Systems)
  • Microsoft Internet Explorer 7 (Windows Server 2008 for x64-based Systems Service Pack 2)
  • Microsoft Internet Explorer 7 (Windows Vista Service Pack 1)
  • Microsoft Internet Explorer 7 (Windows Vista Service Pack 2)
  • Microsoft Internet Explorer 7 (Windows Vista x64 Edition Service Pack 1)
  • Microsoft Internet Explorer 7 (Windows Vista x64 Edition Service Pack 2)
  • Microsoft Internet Explorer 7 (Windows XP Service Pack 3)
  • Microsoft Internet Explorer 8 (Windows Server 2008 for 32-bit Systems Service Pack 2)
  • Microsoft Internet Explorer 8 (Windows Server 2008 for 32-bit Systems)
  • Microsoft Internet Explorer 8 (Windows Server 2008 for x64-based Systems)
  • Microsoft Internet Explorer 8 (Windows Server 2008 R2 for Itanium-based Systems)
  • Microsoft Internet Explorer 8 (Windows Server 2008 R2 for x64-based Systems)
  • Microsoft Internet Explorer 8 (Windows Vista Service Pack 1)
  • Microsoft Internet Explorer 8 (Windows Vista Service Pack 2)
  • Microsoft Internet Explorer 8 (Windows Vista x64 Edition Service Pack 1)
  • Microsoft Internet Explorer 8 (Windows Vista x64 Edition Service Pack 2)
  • Microsoft Internet Explorer 8 (Windows XP Professional x64 Edition Service Pack 2)
  • Microsoft Internet Explorer 8 (Windows XP Service Pack 3)

Featured Stories