Toutes les Menaces

Virus

Hackers

Spams

Whole site    Viruses
  
A propos des Hackers
Analyses
News
Glossaire



 
Encyclopédie Virus
Encyclopédie Virus

Découvrez tous les vers, virus, Trojans et plus dans notre Encyclopédie Virus.

A propos du Spam
A propos du Spam

En savoir plus sur les spams et les spammeurs dans notre section A propos du Spam.

 

  Home / Hackers / A propos des Hackers / Vulnérabilités des logiciels / Exemples et Descriptions / SA23655

Microsoft XML Core Services Multiple Vulnerabilities

Secunia ID

SA23655

CVE-ID

CVE-2007-0099, CVE-2008-4029, CVE-2008-4033

Date de publication

09 Jan 2007

Dernier changement

30 Apr 2009

Niveau critique

Hautement critique

Etat de la solution

Correctif de l'éditeur (avec correctif)

Logiciel

Microsoft Expression Web 1.x
Microsoft Expression Web 2.x
Microsoft Office 2003 Professional Edition
Microsoft Office 2003 Small Business Edition
Microsoft Office 2003 Standard Edition
Microsoft Office 2003 Student and Teacher Edition
Microsoft Office 2007
Microsoft Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats
Microsoft Office Groove Server 2007
Microsoft Office SharePoint Server 2007
Microsoft Office Word Viewer 2003
Microsoft XML Core Services (MSXML) 3.x
Microsoft XML Core Services (MSXML) 4.x
Microsoft XML Core Services (MSXML) 5.x
Microsoft XML Core Services (MSXML) 6.x

A distance

Impact
DoS (déni de service)

Il s'agit des vulnérabilités allant de la consommation excessive de ressources (c.-à-d. que le système utilise beaucoup de mémoire) jusqu'au plantage de l'application ou du système.


Accès au système

Il s'agit des vulnérabilités dans lesquelles un individu malveillant peut accéder au système et exécuter un code arbitraire sous les privileges d'un utilisateur local.


Cross-Site Scripting

Les vulnérabilités de type cross-site scripting permettent à un tiers de manipuler le contenu ou le comportement d'une application Web dans le navigateur de l'utilisateur sans compromettre le système sous-jacent.

Différentes vulnérabilités en rapport avec le cross-site scripting figurent également dans cette catégorie dont l'insertion de script et les attaques de type cross-site request forgery (XSRF).

Les vulnérabilités de type cross-site scripting sont souvent utilisées contre des utilisateurs particuliers d'un site afin de voler leurs identifiants ou de réaliser des attaques d'usurpation d'adresse IP.


Description

Une description detaillee de la vulnerabilite est disponible sur la version anglaise du site.

Solution

Appliquer les correctifs.

-- Windows 2000 --

Windows 2000 SP4 and Microsoft XML Core Services 3.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=559cd4b6-24b7-4e60-8749-37d9b833d3eb

Windows 2000 SP4 and Microsoft XML Core Services 4.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=96a4413c-5261-4f69-83d0-932c430abd14

Windows 2000 SP4 and Microsoft XML Core Services 6.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=59914795-60c7-4ebe-828d-f28cb457e6e3

-- Windows XP --

Windows XP SP2 and Microsoft XML Core Services 3.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=6ed1a087-97e2-4283-9b53-b7b046654d08

Windows XP SP3 and Microsoft XML Core Services 3.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=6ed1a087-97e2-4283-9b53-b7b046654d08

Windows XP SP2/SP3 and Microsoft XML Core Services 4.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=96a4413c-5261-4f69-83d0-932c430abd14

Windows XP SP2 and Microsoft XML Core Services 6.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=59914795-60c7-4ebe-828d-f28cb457e6e3

Windows XP SP3 and Microsoft XML Core Services 6.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=7493fa37-2cbf-4d66-8690-d50d63da4096

Windows XP Professional x64 Edition (optionally with SP2) and Microsoft XML Core Services 3.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=1b79f220-ebfc-49c1-963b-58bbda21b6e7

Windows XP Professional x64 Edition (optionally with SP2) and Microsoft XML Core Services 4.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=96a4413c-5261-4f69-83d0-932c430abd14

Windows XP Professional x64 Edition (optionally with SP2) and Microsoft XML Core Services 6.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=59914795-60c7-4ebe-828d-f28cb457e6e3

-- Windows Server 2003 --

Windows Server 2003 SP1/SP2 and Microsoft XML Core Services 3.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=0a0f8385-e908-4b5f-b9bf-80b7dabfcafd

Windows Server 2003 SP1/SP2 and Microsoft XML Core Services 4.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=96a4413c-5261-4f69-83d0-932c430abd14

Windows Server 2003 SP1/SP2 and Microsoft XML Core Services 6.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=59914795-60c7-4ebe-828d-f28cb457e6e3

Windows Server 2003 x64 Edition (optionally with SP2) and Microsoft XML Core Services 3.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=347c8c83-4269-4a0e-af6f-4be2e824d22b

Windows Server 2003 x64 Edition (optionally with SP2) and Microsoft XML Core Services 4.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=96a4413c-5261-4f69-83d0-932c430abd14

Windows Server 2003 x64 Edition (optionally with SP2) and Microsoft XML Core Services 6.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=59914795-60c7-4ebe-828d-f28cb457e6e3

Windows Server 2003 with SP1/SP2 for Itanium-based Systems and Microsoft XML Core Services 3.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=3a65e1cd-eb4e-44b6-8868-a5a84be2cb32

Windows Server 2003 with SP1/SP2 for Itanium-based Systems and Microsoft XML Core Services 4.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=96a4413c-5261-4f69-83d0-932c430abd14

Windows Server 2003 with SP1/SP2 for Itanium-based Systems and Microsoft XML Core Services 6.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=59914795-60c7-4ebe-828d-f28cb457e6e3

-- Windows Vista --

Windows Vista and Microsoft XML Core Services 3.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=affbc957-1867-4bbe-924d-6f0696ae0895

Windows Vista SP1 and Microsoft XML Core Services 3.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=affbc957-1867-4bbe-924d-6f0696ae0895

Windows Vista (optionally with SP1/SP2) and Microsoft XML Core Services 4.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=96a4413c-5261-4f69-83d0-932c430abd14

Windows Vista and Microsoft XML Core Services 6.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=cb6c4315-8c6d-43af-978b-b190b1a1577a

Windows Vista SP1 and Microsoft XML Core Services 6.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=cb6c4315-8c6d-43af-978b-b190b1a1577a

Windows Vista x64 Edition and Microsoft XML Core Services 3.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=b01a5f31-8c57-4c5c-909e-b37caf0439b0

Windows Vista x64 Edition SP1 and Microsoft XML Core Services 3.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=b01a5f31-8c57-4c5c-909e-b37caf0439b0

Windows Vista x64 Edition (optionally with SP1/SP2) and Microsoft XML Core Services 4.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=96a4413c-5261-4f69-83d0-932c430abd14

Windows Vista x64 Edition and Microsoft XML Core Services 6.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=39443046-2093-4c87-ac7b-679deab96414

Windows Vista x64 Edition SP1 and Microsoft XML Core Services 6.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=39443046-2093-4c87-ac7b-679deab96414

-- Windows Server 2008 --

Windows Server 2008 for 32-bit Systems and Microsoft XML Core Services 3.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=90a04164-4d02-4ce9-b3d8-bddb1ec27618

Windows Server 2008 for 32-bit Systems (optionally with SP2) and Microsoft XML Core Services 4.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=96a4413c-5261-4f69-83d0-932c430abd14

Windows Server 2008 for 32-bit Systems and Microsoft XML Core Services 6.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=dea9f227-967f-47c7-bb2a-ed68f13645d9

Windows Server 2008 for x64-based Systems and Microsoft XML Core Services 3.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=b7bfe3f4-835f-402c-95b5-6d49b6935308

Windows Server 2008 for x64-based Systems (optionally with SP2) and Microsoft XML Core Services 4.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=96a4413c-5261-4f69-83d0-932c430abd14

Windows Server 2008 for x64-based Systems and Microsoft XML Core Services 6.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=f16e2a5f-37fd-4ee1-aef0-597214323dc4

Windows Server 2008 for Itanium-based Systems and Microsoft XML Core Services 3.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=4e0d1efe-70ac-459b-b330-c0149b74f520

Windows Server 2008 for Itanium-based Systems (optionally with SP2) and Microsoft XML Core Services 4.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=96a4413c-5261-4f69-83d0-932c430abd14

Windows Server 2008 for Itanium-based Systems and Microsoft XML Core Services 6.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=d4ae74e2-1b09-4a99-8cf5-8a8ca8ac6f7f

-- Microsoft Office --

Office 2003 SP3 and Microsoft XML Core Services 5.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=7ad891a8-c3bb-4479-8282-13d629c410e3

Microsoft Word Viewer 2003 SP3 and Microsoft XML Core Services 5.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=7ad891a8-c3bb-4479-8282-13d629c410e3

2007 Microsoft Office System and Microsoft XML Core Services 5.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=27b06ee8-570a-4dc2-a230-c70d4a706245

2007 Microsoft Office System SP1 and Microsoft XML Core Services 5.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=27b06ee8-570a-4dc2-a230-c70d4a706245

Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats and Microsoft XML Core Services 5.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=27b06ee8-570a-4dc2-a230-c70d4a706245

Office Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1 and Microsoft XML Core Services 5.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=27b06ee8-570a-4dc2-a230-c70d4a706245

Microsoft Expression Web and Microsoft XML Core Services 5.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=27b06ee8-570a-4dc2-a230-c70d4a706245

Microsoft Expression Web 2 and Microsoft XML Core Services 5.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=27b06ee8-570a-4dc2-a230-c70d4a706245

Office SharePoint Server 2007 (32-bit editions) and Microsoft XML Core Services 5.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=a208f2b5-2b0d-43bb-8f8a-58d4a3fc64f5

Office SharePoint Server 2007 SP1 (32-bit editions) and Microsoft XML Core Services 5.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=a208f2b5-2b0d-43bb-8f8a-58d4a3fc64f5

Office SharePoint Server 2007 (optionally with SP1) (64-bit editions) and Microsoft XML Core Services 5.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=0735f4af-e32b-4970-bed7-b2b9323cf54c

Office Groove Server 2007 and Microsoft XML Core Services 5.0:
http://www.microsoft.com/downloads/details.aspx?FamilyId=0735f4af-e32b-4970-bed7-b2b9323cf54c




 

Copyright © 1996 - 2010
Kaspersky Lab
Industry-leading Antivirus Software
All rights reserved
 

Email: webmaster@viruslist.com