晓峰's profileMasaki’s SpacePhotosBlogListsMore Tools Help

Blog


    09/09/2009

    Microsoft 发布 2009 年 9 月安全公告

    ============================================================
    不同安全级别的安全公告
    ============================================================

    「2009 年 9 月发布的安全公告摘要」详细信息,请访问。
    http://www.microsoft.com/china/technet/security/bulletin/ms09-sep.mspx

    ------------------------------------------------------------
    ■ 严重
    ------------------------------------------------------------

    MS09-045 JScript 脚本引擎中的漏洞可能允许远程执行代码 (971961)

      - 受影响的软件:
        - Microsoft Windows 2000 Service Pack 4 上的 
          JScript 5.1 以及 JScript 5.6
        - Windows XP Service Pack 2 以及
          Windows XP Service Pack 3 上的
          JScript 5.6, JScript 5.7 以及 JScript 5.8
        - Windows XP Professional x64 Edition Service Pack 2 上的
          JScript 5.6, JScript 5.7 以及 JScript 5.8
        - Windows Server 2003 Service Pack 2 上的
          JScript 5.6, JScript 5.7 以及 JScript 5.8
        - Windows Server 2003 x64 Edition Service Pack 2 上的
          JScript 5.6, JScript 5.7 以及 JScript 5.8
        - Windows Server 2003 with SP2 for Itanium-based Systems 上的
          JScript 5.6 以及 JScript 5.7
        - Windows Vista,
          Windows Vista Service Pack 1 以及
          Windows Vista Service Pack 2 上的
          JScript 5.7 以及 JScript 5.8
        - Windows Vista x64 Edition,
          Windows Vista x64 Edition Service Pack 1 以及
          Windows Vista x64 Edition Service Pack 2 上的
          JScript 5.7 以及 JScript 5.8
        - Windows Server 2008 for 32-bit Systems 以及
          Windows Server 2008 for 32-bit Systems Service Pack 2 上的
          JScript 5.7 以及 JScript 5.8
          (Windows Server 2008 Server Core 安装也受影响)
        - Windows Server 2008 for x64-based Systems and
          Windows Server 2008 for x64-based Systems Service Pack 2 上的
          JScript 5.7 and JScript 5.8
          (Windows Server 2008 Server Core 安装也受影响)
        - Windows Server 2008 for Itanium-based Systems 以及
          Windows Server 2008 for Itanium-based Systems Service Pack 2 上的
          JScript 5.7
        - 漏洞影响: 远程执行代码

    MS09-049 无线局域网 AutoConfig 服务中的漏洞可能允许远程执行代码 (970710)

      - 受影响的软件:
         - Windows Vista,
          Windows Vista Service Pack 1 以及
          Windows Vista Service Pack 2
        - Windows Vista x64 Edition,
          Windows Vista x64 Edition Service Pack 1 以及
          Windows Vista x64 Edition Service Pack 2
        - Windows Server 2008 for 32-bit Systems 以及
          Windows Server 2008 for 32-bit Systems Service Pack 2
          (Windows Server 2008 Server Core 安装不受影响)
        - Windows Server 2008 for x64-based Systems and
          Windows Server 2008 for x64-based Systems Service Pack 2
          (Windows Server 2008 Server Core 安装不受影响)

        - 漏洞影响: 远程执行代码

    MS09-047 Windows Media Format 中的漏洞可能允许远程执行代码 (973812)

      - 受影响的软件:
        - Microsoft Windows 2000 Service Pack 4 上的
          Windows Media Format Runtime 9.0
        - Windows XP Service Pack 2 以及
          Windows XP Service Pack 3 上的
          Windows Media Format Runtime 9.0,
          Windows Media Format Runtime 9.5 以及
          Windows Media Format Runtime 11
        - Windows XP Professional x64 Edition Service Pack 2 上的
          Windows Media Format Runtime 9.5,
          Windows Media Format Runtime 9.5 x64 Edition 以及
          Windows Media Format Runtime 11
        - Windows Server 2003 Service Pack 2 上的
          Windows Media Format Runtime 9.5
        - Windows Server 2003 Service Pack 2 上的
          Windows Media Services 9.1
        - Windows Server 2003 x64 Edition Service Pack 2 上的
          Windows Media Format Runtime 9.5 以及
          Windows Media Format Runtime 9.5 x64 Edition
        - Windows Server 2003 x64 Edition Service Pack 2 上的
          Windows Media Services 9.1
        - Windows Vista,
          Windows Vista Service Pack 1 以及
          Windows Vista Service Pack 2 上的
          Windows Media Format Runtime 11 以及
          Microsoft Media Foundation
        - Windows Vista x64 Edition,
          Windows Vista x64 Edition Service Pack 1 以及
          Windows Vista x64 Edition Service Pack 2 上的
          Windows Media Format Runtime 11 以及
          Microsoft Media Foundation
        - Windows Server 2008 for 32-bit Systems 以及
          Windows Server 2008 for 32-bit Systems Service Pack 2 上的
          Windows Media Format Runtime 11 以及
          Microsoft Media Foundation
          (Windows Server 2008 Server Core 安装不受影响)
        - Windows Server 2008 for 32-bit Systems 以及
          Windows Server 2008 for 32-bit Systems Service Pack 2 上的
          Windows Media Services 2008
          (Windows Server 2008 Server Core 安装也受影响)
        - Windows Server 2008 for x64-based Systems 以及
          Windows Server 2008 for x64-based Systems Service Pack 2 上的
          Windows Media Format Runtime 11 以及
          Microsoft Media Foundation
          (Windows Server 2008 Server Core 安装不受影响)
        - Windows Server 2008 for x64-based Systems 以及
          Windows Server 2008 for x64-based Systems Service Pack 2 上的
          Windows Media Services 2008
          (Windows Server 2008 Server Core 安装也受影响)

        - 漏洞影响: 远程执行代码

    MS09-048 Windows TCP/IP 中的漏洞可能允许远程执行代码 (967723)

      - 受影响的软件:
        - Microsoft Windows 2000 Service Pack 4
          (没有可用的更新。 有关详细信息,请参阅与此安全更新相关的常见问题 (FAQ) 条目。)
        - Windows XP Service Pack 2、
          Windows XP Service Pack 3 以及
          Windows XP Professional x64 Edition Service Pack 2
          (没有可用的更新。 有关详细信息,请参阅与此安全更新相关的常见问题 (FAQ) 条目。)
        - Windows Server 2003 Service Pack 2
        - Windows Server 2003 x64 Edition Service Pack 2
        - Windows Server 2003 with SP2 for Itanium-based Systems
        - Windows Vista,
          Windows Vista Service Pack 1 以及
          Windows Vista Service Pack 2
        - Windows Vista x64 Edition,
          Windows Vista x64 Edition Service Pack 1 以及
          Windows Vista x64 Edition Service Pack 2
        - Windows Server 2008 for 32-bit Systems 以及
          Windows Server 2008 for 32-bit Systems Service Pack 2
          (Windows Server 2008 Server Core 安装也受影响)
        - Windows Server 2008 for x64-based Systems 以及
          Windows Server 2008 for x64-based Systems Service Pack 2
          (Windows Server 2008 Server Core 安装也受影响)
        - Windows Server 2008 for Itanium-based Systems 以及
          Windows Server 2008 for Itanium-based Systems Service Pack 2

        - 漏洞影响: 远程执行代码

    MS09-046 DHTML 编辑组件 ActiveX 控件中的安全漏洞可能允许远程执行代码 (956844)

      - 受影响的软件:
        - Microsoft Windows 2000 Service Pack 4
        - Windows XP Service Pack 2 以及
          Windows XP Service Pack 3
        - Windows XP Professional x64 Edition Service Pack 2
        - Windows Server 2003 Service Pack 2
        - Windows Server 2003 x64 Edition Service Pack 2
        - Windows Server 2003 with SP2 for Itanium-based Systems

        - 漏洞影响: 远程执行代码

    Comments

    Please wait...
    Sorry, the comment you entered is too long. Please shorten it.
    You didn't enter anything. Please try again.
    Sorry, we can't add your comment right now. Please try again later.
    To add a comment, you need permission from your parent. Ask for permission
    Your parent has turned off comments.
    Sorry, we can't delete your comment right now. Please try again later.
    You've exceeded the maximum number of comments that can be left in one day. Please try again in 24 hours.
    Your account has had the ability to leave comments disabled because our systems indicate that you may be spamming other users. If you believe that your account has been disabled in error please contact Windows Live support.
    Complete the security check below to finish leaving your comment.
    The characters you type in the security check must match the characters in the picture or audio.

    To add a comment, sign in with your Windows Live ID (if you use Hotmail, Messenger, or Xbox LIVE, you have a Windows Live ID). Sign in


    Don't have a Windows Live ID? Sign up

    Trackbacks

    The trackback URL for this entry is:
    http://jhmasuji.spaces.live.com/blog/cns!560842B1BEE145BD!4044.trak
    Weblogs that reference this entry
    • None