Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

Short Name

HTTP:STC:DL:COM-CLSID-DLL

Severity

High

Recommended

No

Recommended Action

Drop

Category

HTTP

Keywords

Microsoft Windows Insecure Library Loading

Release Date

2011/09/12

Update Number

1992

Supported Platforms

idp-4.0+, isg-3.0+, j-series-9.5+, mx-9.4+, srx-9.2+, srx-branch-9.4+, vsrx-12.1+

HTTP: Microsoft Windows Insecure Library Loading


This signature detects attempts to exploit a known vulnerability against in Microsoft Windows shell extensions loading. A successful attack can lead to arbitrary code execution.

Extended Description

Multiple Microsoft products are prone to a vulnerability that lets attackers execute arbitrary code. An attacker can exploit this issue by enticing a legitimate user to use the vulnerable application to open a file from a network share location that contains a specially crafted Dynamic Link Library (DLL) file.

Affected Products

  • Avaya CallPilot 4.0
  • Avaya CallPilot 5.0
  • Avaya Communication Server 1000 Telephony Manager 3.0
  • Avaya Communication Server 1000 Telephony Manager 4.0
  • Avaya Communication Server 1000 Telephony Manager
  • Avaya Conferencing Standard Edition 6.0
  • Avaya Conferencing Standard Edition 6.0 SP1
  • Avaya Meeting Exchange - Client Registration Server
  • Avaya Meeting Exchange - Recording Server
  • Avaya Meeting Exchange - Streaming Server
  • Avaya Meeting Exchange - Web Conferencing Server
  • Avaya Meeting Exchange - Webportal
  • Avaya Messaging Application Server 5.2
  • Microsoft Internet Explorer 8
  • Microsoft Internet Explorer 9
  • Microsoft PowerPoint 2010
  • Microsoft Windows 7
  • Microsoft Windows 7 for 32-bit Systems SP1
  • Microsoft Windows 7 for 32-bit Systems
  • Microsoft Windows 7 for Itanium-based Systems SP1
  • Microsoft Windows 7 for Itanium-based Systems
  • Microsoft Windows 7 for x64-based Systems SP1
  • Microsoft Windows 7 for x64-based Systems
  • Microsoft Windows Server 2008 R2
  • Microsoft Windows Server 2003 R2
  • Microsoft Windows Server 2003 R2 Compute Cluster
  • Microsoft Windows Server 2003 R2 Datacenter
  • Microsoft Windows Server 2003 R2 Enterprise
  • Microsoft Windows Server 2003 Datacenter Edition SP1
  • Microsoft Windows Server 2003 Datacenter Edition SP1 Beta 1
  • Microsoft Windows Server 2003 Datacenter Edition
  • Microsoft Windows Server 2003 Datacenter Edition Itanium SP1
  • Microsoft Windows Server 2003 Datacenter Edition Itanium SP1 Beta 1
  • Microsoft Windows Server 2003 Datacenter Edition Itanium
  • Microsoft Windows Server 2003 Datacenter x64 Edition SP2
  • Microsoft Windows Server 2003 Datacenter x64 Edition
  • Microsoft Windows Server 2003 Enterprise Edition SP1
  • Microsoft Windows Server 2003 Enterprise Edition SP1 Beta 1
  • Microsoft Windows Server 2003 Enterprise Edition
  • Microsoft Windows Server 2003 Enterprise Edition Itanium SP1
  • Microsoft Windows Server 2003 Enterprise Edition Itanium SP1 Beta 1
  • Microsoft Windows Server 2003 Enterprise Edition Itanium SP2
  • Microsoft Windows Server 2003 Enterprise Edition Itanium Sp2 Itanium
  • Microsoft Windows Server 2003 Enterprise Edition Itanium
  • Microsoft Windows Server 2003 Enterprise x64 Edition SP2
  • Microsoft Windows Server 2003 Enterprise x64 Edition
  • Microsoft Windows Server 2003 Itanium SP1
  • Microsoft Windows Server 2003 Itanium SP2
  • Microsoft Windows Server 2003 Itanium
  • Microsoft Windows Server 2003 R2 Datacenter Edition
  • Microsoft Windows Server 2003 R2 Datacenter Edition SP1
  • Microsoft Windows Server 2003 R2 Datacenter Edition SP2
  • Microsoft Windows Server 2003 R2 Enterprise Edition
  • Microsoft Windows Server 2003 R2 Enterprise Edition SP1
  • Microsoft Windows Server 2003 R2 Enterprise Edition SP2
  • Microsoft Windows Server 2008 Datacenter Edition Release Candidate
  • Microsoft Windows Server 2008 Datacenter Edition SP2
  • Microsoft Windows Server 2008 Datacenter Edition
  • Microsoft Windows Server 2008 Enterprise Edition Release Candidate
  • Microsoft Windows Server 2008 Enterprise Edition SP2
  • Microsoft Windows Server 2008 Enterprise Edition
  • Microsoft Windows Server 2008 for 32-bit Systems SP2
  • Microsoft Windows Server 2008 for 32-bit Systems
  • Microsoft Windows Server 2008 for Itanium-based Systems R2
  • Microsoft Windows Server 2008 for Itanium-based Systems SP2
  • Microsoft Windows Server 2008 for Itanium-based Systems
  • Microsoft Windows Server 2008 for x64-based Systems R2
  • Microsoft Windows Server 2008 for x64-based Systems SP2
  • Microsoft Windows Server 2008 for x64-based Systems
  • Microsoft Windows Server 2008 R2 Datacenter SP1
  • Microsoft Windows Server 2008 R2 Datacenter
  • Microsoft Windows Server 2008 R2 Enterprise Edition
  • Microsoft Windows Server 2008 R2 for x64-based Systems SP1
  • Microsoft Windows Server 2008 R2 Itanium SP1
  • Microsoft Windows Server 2008 R2 Itanium
  • Microsoft Windows Server 2008 R2 Standard Edition
  • Microsoft Windows Server 2008 R2 x64 SP1
  • Microsoft Windows Server 2008 R2 x64
  • Microsoft Windows Server 2008 Standard Edition R2
  • Microsoft Windows Server 2008 Standard Edition R2 SP1
  • Microsoft Windows Vista 1.0
  • Microsoft Windows Vista 2.0
  • Microsoft Windows Vista 3.0
  • Microsoft Windows Vista Beta
  • Microsoft Windows Vista Beta 1
  • Microsoft Windows Vista Beta 2
  • Microsoft Windows Vista Business
  • Microsoft Windows Vista Business SP1
  • Microsoft Windows Vista Business SP2
  • Microsoft Windows Vista Enterprise
  • Microsoft Windows Vista Enterprise SP1
  • Microsoft Windows Vista Enterprise SP2
  • Microsoft Windows Vista Home Basic
  • Microsoft Windows Vista Home Basic SP1
  • Microsoft Windows Vista Home Basic SP2
  • Microsoft Windows Vista Home Premium
  • Microsoft Windows Vista Home Premium SP1
  • Microsoft Windows Vista Home Premium SP2
  • Microsoft Windows Vista SP1
  • Microsoft Windows Vista SP2
  • Microsoft Windows Vista SP2 Beta
  • Microsoft Windows Vista Ultimate
  • Microsoft Windows Vista Ultimate SP1
  • Microsoft Windows Vista Ultimate SP2
  • Microsoft Windows Vista
  • Microsoft Windows Vista Business 64-bit edition SP1
  • Microsoft Windows Vista Business 64-bit edition SP2
  • Microsoft Windows Vista Business 64-bit edition
  • Microsoft Windows Vista December CTP Gold
  • Microsoft Windows Vista December CTP SP1
  • Microsoft Windows Vista December CTP SP2
  • Microsoft Windows Vista December CTP X64
  • Microsoft Windows Vista December CTP
  • Microsoft Windows Vista Enterprise 64-bit edition SP1
  • Microsoft Windows Vista Enterprise 64-bit edition SP2
  • Microsoft Windows Vista Enterprise 64-bit edition
  • Microsoft Windows Vista Home Basic 64-bit edition SP1
  • Microsoft Windows Vista Home Basic 64-bit edition Sp1 X64
  • Microsoft Windows Vista Home Basic 64-bit edition SP2
  • Microsoft Windows Vista Home Basic 64-bit edition Sp2 X64
  • Microsoft Windows Vista Home Basic 64-bit edition
  • Microsoft Windows Vista Home Premium 64-bit edition SP1
  • Microsoft Windows Vista Home Premium 64-bit edition SP2
  • Microsoft Windows Vista Home Premium 64-bit edition
  • Microsoft Windows Vista Ultimate 64-bit edition SP1
  • Microsoft Windows Vista Ultimate 64-bit edition SP2
  • Microsoft Windows Vista Ultimate 64-bit edition
  • Microsoft Windows Vista x64 Edition SP1
  • Microsoft Windows Vista x64 Edition SP2
  • Microsoft Windows Vista x64 Edition
  • Microsoft Windows XP - Gold 64-Bit-2002
  • Microsoft Windows XP Gold Embedded
  • Microsoft Windows XP - Gold Home
  • Microsoft Windows XP Gold Media Center
  • Microsoft Windows XP Gold Professional
  • Microsoft Windows XP Gold Tablet Pc
  • Microsoft Windows XP - Gold X64
  • Microsoft Windows XP - Sp1 X64
  • Microsoft Windows XP
  • Microsoft Windows XP
  • Microsoft Windows XP 64-bit Edition SP1
  • Microsoft Windows XP 64-bit Edition
  • Microsoft Windows XP 64-bit Edition Version 2003 SP1
  • Microsoft Windows XP 64-bit Edition Version 2003
  • Microsoft Windows XP Embedded SP1
  • Microsoft Windows XP Embedded SP2
  • Microsoft Windows XP Embedded SP3
  • Microsoft Windows XP Embedded
  • Microsoft Windows XP Embedded SP2 Feature Pack 2007
  • Microsoft Windows XP Embedded Update Rollup 1.0
  • Microsoft Windows XP Gold
  • Microsoft Windows XP Home SP1
  • Microsoft Windows XP Home SP2
  • Microsoft Windows XP Home SP3
  • Microsoft Windows XP Home
  • Microsoft Windows XP Media Center Edition SP1
  • Microsoft Windows XP Media Center Edition SP2
  • Microsoft Windows XP Media Center Edition SP3
  • Microsoft Windows XP Media Center Edition
  • Microsoft Windows XP Media Center Edition 2005 SP3
  • Microsoft Windows XP Professional SP1
  • Microsoft Windows XP Professional SP2
  • Microsoft Windows XP Professional SP3
  • Microsoft Windows XP Professional
  • Microsoft Windows XP Professional x64 Edition SP2
  • Microsoft Windows XP Professional x64 Edition SP3
  • Microsoft Windows XP Professional x64 Edition
  • Microsoft Windows XP Service Pack 3
  • Microsoft Windows XP Tablet PC Edition SP1
  • Microsoft Windows XP Tablet PC Edition SP2
  • Microsoft Windows XP Tablet PC Edition SP3
  • Microsoft Windows XP Tablet PC Edition
  • Microsoft Word 2010

References

  • BugTraq: 47741
  • CVE: CVE-2011-1991

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out