Microsoft MSHTML Remote Code Execution Vulnerability
MSHTML 엔진이 입력을 부적절하게 검증하는 방식에 원격 코드 실행 취약점, 일명 "MSHTML Engine Remote Code Execution Vulnerability"가 존재합니다. 이는 Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus에 영향을 미칩니다.
MSHTML 엔진이 입력을 부적절하게 검증하는 방식에 원격 코드 실행 취약점, 일명 "MSHTML Engine Remote Code Execution Vulnerability"가 존재합니다. 이는 Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus에 영향을 미칩니다.
한국어 설명은 영문 원문을 기준으로 제공됩니다. 제품명·버전·보안 식별자는 아래 원문과 함께 확인할 수 있습니다.
영문 원문 보기
A remote code execution vulnerability exists in the way that the MSHTML engine inproperly validates input, aka "MSHTML Engine Remote Code Execution Vulnerability." This affects Microsoft Office, Microsoft Office Word Viewer, Internet Explorer 9, Internet Explorer 11, Microsoft Excel Viewer, Internet Explorer 10, Office 365 ProPlus.
영향 제품·버전
제품 Microsoft MSHTML
영향 버전 Microsoft MSHTML 2010 Service Pack 2 (32-bit editions), 2010 Service Pack 2 (64-bit editions), 2013 RT Service Pack 1, 2013 Service Pack 1 (32-bit editions), 2013 Service Pack 1 (64-bit editions), 2016 (32-bit edition), 2016 (64-bit edition), 2019 for 32-bit editions, 2019 for 64-bit editions, Microsoft Office Word Viewer, Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for x64-based Systems Service Pack 2, Windows 10 for 32-bit Systems, Windows 10 for x64-based Systems, Windows 10 1607 for 32-bit Systems, Windows 10 1607 for x64-based Systems, Windows 10 1703 for 32-bit Systems, Windows 10 1703 for x64-based Systems, Windows 10 1709 for 32-bit Systems, Windows 10 1709 for ARM64-based Systems
Microsoft MSHTML의 현재 전체 버전이 공식 영향 범위(Microsoft MSHTML 2010 Service Pack 2 (32-bit editions), 2010 Service Pack 2 (64-bit editions), 2013 RT Service Pack 1, 2013 Service Pack 1 (32-bit editions), 2013 Service Pack 1 (64-bit editions), 2016 (32-bit edition), 2016 (64-bit edition), 2019 for 32-bit editions, 2019 for 64-bit editions, Microsoft Office Word Viewer, Windows Server 2008 for 32-bit Systems Service Pack 2, Windows Server 2008 for x64-based Systems Service Pack 2, Windows 10 for 32-bit Systems, Windows 10 for x64-based Systems, Windows 10 1607 for 32-bit Systems, Windows 10 1607 for x64-based Systems, Windows 10 1703 for 32-bit Systems, Windows 10 1703 for x64-based Systems, Windows 10 1709 for 32-bit Systems, Windows 10 1709 for ARM64-based Systems)에 포함되는지 확인합니다. OS를 선택하면 해당 OS의 제품·패키지·KB·APAR 확인 명령만 표시됩니다.
조치방안
Apply updates per vendor instructions.
조치 후 확인사항
패치 후 같은 명령으로 전체 버전을 다시 확인해 수정 버전은 공급사 공식자료 확인 필요 기준을 충족하는지 확인합니다. 이어서 명령어·코드 인젝션 관련 오류·공격 흔적이 새로 발생하지 않는지 확인합니다.