Short Name |
HTTP:DLL-REQ-VIA-WEBDAV
|
Severity |
High
|
Recommended |
Yes
|
Recommended Action |
Drop
|
Category |
HTTP
|
Keywords |
DLL File Download via WebDAV
|
Release Date |
2010/09/08
|
Update Number |
1768
|
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+
|
HTTP: DLL File Download via WebDAV
This signature detects Microsoft Windows Dynamically Link Libraries (DLL's) transferred via WebDAV. Vulnerabilities in Microsoft Windows allow an attacker to reference a malicious remote DLL file through a Web page, which when the page is accessed, overwrites a local DLL, resulting in arbitrary code execution.
Extended Description
Microsoft Windows is prone to an arbitrary-code-execution vulnerability that affects the Media Center.
Attackers can exploit this vulnerability to execute arbitrary code in the context of the user running the vulnerable application.
Affected Products
- Microsoft Windows 7 for 32-bit Systems SP1
- Microsoft Windows 7 for 32-bit Systems
- Microsoft Windows 7 for x64-based Systems SP1
- Microsoft Windows 7 for x64-based Systems
- Microsoft Windows Media Center TV Pack for Windows Vista 32-bit edition
- Microsoft Windows Media Center TV Pack for Windows Vista 64-bit edition
- Microsoft Windows Vista Business SP1
- Microsoft Windows Vista Business SP2
- Microsoft Windows Vista Enterprise SP1
- Microsoft Windows Vista Enterprise SP2
- Microsoft Windows Vista Home Basic SP1
- Microsoft Windows Vista Home Basic SP2
- Microsoft Windows Vista Home Premium SP1
- Microsoft Windows Vista Home Premium SP2
- Microsoft Windows Vista SP1
- Microsoft Windows Vista SP2
- Microsoft Windows Vista Ultimate SP1
- Microsoft Windows Vista Ultimate SP2
- Microsoft Windows Vista x64 Edition SP1
- Microsoft Windows Vista x64 Edition SP2
- Microsoft Windows Vista x64 Edition
References