Microsoft Windows TS WebProxy Directory Traversal Vulnerability
Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold 및 R2, Windows RT Gold 및 8.1의 TS WebProxy(일명 TSWbPrxy) 구성 요소에 존재하는 디렉터리 탐색 취약점으로 인해 원격 공격자가 실행 파일의 조작된 경로명을 통해 권한을 획득할 수 있습니다. 이는 Low Integrity에서 Medium Integrity로의 전환으로 입증되었으며, 이 취약점은 "디렉터리 탐색 권한 상승 취약점"이라고도 합니다.
Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold 및 R2, Windows RT Gold 및 8.1의 TS WebProxy(일명 TSWbPrxy) 구성 요소에 존재하는 디렉터리 탐색 취약점으로 인해 원격 공격자가 실행 파일의 조작된 경로명을 통해 권한을 획득할 수 있습니다. 이는 Low Integrity에서 Medium Integrity로의 전환으로 입증되었으며, 이 취약점은 "디렉터리 탐색 권한 상승 취약점"이라고도 합니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to gain privileges via a crafted pathname in an executable file, as demonstrated by a transition from Low Integrity to Medium Integrity, aka "Directory Traversal Elevation of Privilege Vulnerability."