Microsoft Windows Object Linking & Embedding (OLE) Remote Code Execution Vulnerability
Microsoft Windows Vista SP2, Windows Server 2008 SP2 및 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold 및 R2, Windows RT Gold 및 8.1에서는 원격 공격자가 Office 문서 내의 조작된 OLE 객체를 통해 임의 코드를 실행할 수 있으며, 이는 2014년 6월부터 10월까지 "Sandworm" 공격을 통해 실제로 악용되었습니다. 이 취약점은 "Windows OLE Remote Code Execution Vulnerability"라고도 합니다.
Microsoft Windows Vista SP2, Windows Server 2008 SP2 및 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold 및 R2, Windows RT Gold 및 8.1에서는 원격 공격자가 Office 문서 내의 조작된 OLE 객체를 통해 임의 코드를 실행할 수 있으며, 이는 2014년 6월부터 10월까지 "Sandworm" 공격을 통해 실제로 악용되었습니다. 이 취약점은 "Windows OLE Remote Code Execution Vulnerability"라고도 합니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object in an Office document, as exploited in the wild with a "Sandworm" attack in June through October 2014, aka "Windows OLE Remote Code Execution Vulnerability."