Microsoft Silverlight Runtime Remote Code Execution Vulnerability
Microsoft Silverlight 5의 5.1.41212.0 이전 버전은 디코딩 중 음수 오프셋을 잘못 처리합니다. 이로 인해 원격 공격자가 조작된 웹 사이트를 통해 임의의 코드를 실행하거나 서비스 거부(객체 헤더 손상)를 일으킬 수 있으며, 이 취약점은 "Silverlight Runtime Remote Code Execution Vulnerability"로도 알려져 있습니다.
Microsoft Silverlight 5의 5.1.41212.0 이전 버전은 디코딩 중 음수 오프셋을 잘못 처리합니다. 이로 인해 원격 공격자가 조작된 웹 사이트를 통해 임의의 코드를 실행하거나 서비스 거부(객체 헤더 손상)를 일으킬 수 있으며, 이 취약점은 "Silverlight Runtime Remote Code Execution Vulnerability"로도 알려져 있습니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
Microsoft Silverlight 5 before 5.1.41212.0 mishandles negative offsets during decoding, which allows remote attackers to execute arbitrary code or cause a denial of service (object-header corruption) via a crafted web site, aka "Silverlight Runtime Remote Code Execution Vulnerability."