Microsoft Windows Object Linking & Embedding (OLE) Automation Array Remote Code Execution Vulnerability
Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 및 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold 및 R2, Windows RT Gold 및 8.1의 OLE에 포함된 OleAut32.dll은 원격 공격자가 조작된 웹 사이트를 통해 임의 코드를 실행할 수 있게 합니다. 이는 SafeArrayDimen 함수에서 크기 값이 부적절하게 처리되도록 유발하는 배열 차원 재설정 시도로 입증되었으며, 이 취약점은 "Windows OLE Automation Array 원격 코드 실행 취약점"이라고도 합니다.
Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 및 R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold 및 R2, Windows RT Gold 및 8.1의 OLE에 포함된 OleAut32.dll은 원격 공격자가 조작된 웹 사이트를 통해 임의 코드를 실행할 수 있게 합니다. 이는 SafeArrayDimen 함수에서 크기 값이 부적절하게 처리되도록 유발하는 배열 차원 재설정 시도로 입증되었으며, 이 취약점은 "Windows OLE Automation Array 원격 코드 실행 취약점"이라고도 합니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted web site, as demonstrated by an array-redimensioning attempt that triggers improper handling of a size value in the SafeArrayDimen function, aka "Windows OLE Automation Array Remote Code Execution Vulnerability."