Vulnerabilities > CVE-2009-2507 - Unspecified vulnerability in Microsoft Windows 2000, Windows 2003 Server and Windows XP
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
COMPLETE Integrity impact
COMPLETE Availability impact
COMPLETE Summary
A certain ActiveX control in the Indexing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly process URLs, which allows remote attackers to execute arbitrary programs via unspecified vectors that cause a "vulnerable binary" to load and run, aka "Memory Corruption in Indexing Service Vulnerability."
Vulnerable Configurations
Part | Description | Count |
---|---|---|
OS | 7 |
Msbulletin
bulletin_id | MS09-057 |
bulletin_url | |
date | 2009-10-13T00:00:00 |
impact | Remote Code Execution |
knowledgebase_id | 969059 |
knowledgebase_url | |
severity | Important |
title | Vulnerability in Indexing Service Could Allow Remote Code Execution |
Nessus
NASL family | Windows : Microsoft Bulletins |
NASL id | SMB_NT_MS09-057.NASL |
description | The remote host contains the ixsso.dll ActiveX control. This control is included with the Indexing Service. The version of this control installed on the remote host reportedly has an arbitrary code execution vulnerability. A remote attacker could exploit this by tricking a user into requesting a maliciously crafted web page. This vulnerability only affects systems that have the Indexing Service enabled. It is disabled by default. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 42113 |
published | 2009-10-13 |
reporter | This script is Copyright (C) 2009-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/42113 |
title | MS09-057: Vulnerability in Indexing Service Could Allow Remote Code Execution (969059) |
code |
|
Oval
accepted | 2009-11-30T04:00:18.262-05:00 | ||||||||||||||||||||||||||||
class | vulnerability | ||||||||||||||||||||||||||||
contributors |
| ||||||||||||||||||||||||||||
definition_extensions |
| ||||||||||||||||||||||||||||
description | A certain ActiveX control in the Indexing Service in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not properly process URLs, which allows remote attackers to execute arbitrary programs via unspecified vectors that cause a "vulnerable binary" to load and run, aka "Memory Corruption in Indexing Service Vulnerability." | ||||||||||||||||||||||||||||
family | windows | ||||||||||||||||||||||||||||
id | oval:org.mitre.oval:def:6042 | ||||||||||||||||||||||||||||
status | accepted | ||||||||||||||||||||||||||||
submitted | 2009-10-13T13:00:00 | ||||||||||||||||||||||||||||
title | Memory Corruption in Indexing Service Vulnerability | ||||||||||||||||||||||||||||
version | 69 |
Seebug
bulletinFamily | exploit |
description | BUGTRAQ ID: 36629 CVE(CAN) ID: CVE-2009-2507 Windows是微软发布的非常流行的操作系统。 Windows的索引服务所包含的ActiveX控件未正确处理特制Web内容,导致Windows系统上的索引服务中存在内存破坏漏洞。成功利用此漏洞的攻击者可以完全控制受影响的系统。 Microsoft Windows XP SP3 Microsoft Windows XP SP2 Microsoft Windows Server 2003 SP2 Microsoft Windows Server 2003 SP1 Microsoft Windows 2000SP4 临时解决方法: * 注销ixsso.dll 1. 单击“开始”、“运行”,键入"%SystemRoot%\System32\regsvr32.exe" /u ixsso.dll,然后单击“确定”。 2. 此时将出现一个对话框,确认注销过程已成功完成。单击“确定”关闭对话框。 * 阻止在Internet Explorer中运行索引服务ActiveX控件COM对象,将以下文本粘贴于记事本等文本编辑器中,然后使用.reg文件扩展名保存文件。 Windows Registry Editor Version 5.00 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\ActiveX Compatibility\{A4463024-2B6F-11D0-BFBC-0020F8008024}] "Compatibility Flags"=dword:00000400 可以通过双击此.reg文件将其应用到各个系统,还可以使用组策略跨域应用该文件。 * 将Internet Explorer配置为在Internet和本地Intranet安全区域中运行ActiveX控件和活动脚本之前进行提示。 * 将Internet 和本地Intranet安全区域设置设为“高”,以便在这些区域中运行ActiveX控件和活动脚本之前进行提示。 厂商补丁: Microsoft --------- Microsoft已经为此发布了一个安全公告(MS09-057)以及相应补丁: MS09-057:Vulnerability in Indexing Service Could Allow Remote Code Execution (969059) 链接:http://www.microsoft.com/technet/security/Bulletin/MS09-057.mspx?pf=true |
id | SSV:12489 |
last seen | 2017-11-19 |
modified | 2009-10-19 |
published | 2009-10-19 |
reporter | Root |
title | Microsoft Windows索引服务ActiveX控件内存破坏漏洞(MS09-057) |