Windows Packagerè¨å®ã«ãããä»»æã®ã³ã¼ããå®è¡å¯è½ãªèå¼±æ§(MS12-005)ï¼CVE-2012-0013ï¼ã«é¢ããæ¤è¨¼ã¬ãã¼ã

2012/01/17
NTTãã¼ã¿å
端æè¡æ ªå¼ä¼ç¤¾
è¾» 伸å¼
æ³ç° 幸å®
ãæ¦è¦ã
ClickOnceã¢ããªã±ã¼ã·ã§ã³ãå«ãç´°å·¥ãããMicrosoft Officeãã¡ã¤ã«ãã¦ã¼ã¶ãéããå ´åã«ãä»»æã®ã³ã¼ããå®è¡ãããèå¼±æ§ãçºè¦ããã¾ããã
ClickOnceã¨ã¯ã.NET Framework 2.0以éããå©ç¨å¯è½ã¨ãªã£ããªã³ã¯ãã¯ãªãã¯ããã ãã§ã¢ããªã±ã¼ã·ã§ã³ã®å®è¡ãè¡ããã¨ãããã®ã§ãã
æ¬èå¼±æ§ã¯ãClick Onceã¢ããªã±ã¼ã·ã§ã³ã®ãã¡ã¤ã«ã®ç¨®é¡ããWindows Packagerã®å®å
¨ã§ã¯ãªããã¡ã¤ã«ã®ç¨®é¡ã®ãªã¹ãã«å«ã¾ãã¦ããªããã¨ã«ããçºçãã¾ãã
ãã®èå¼±æ§ã«ãããç´°å·¥ããããã¡ã¤ã«ãé²è¦§ããããã¨ã§ããã¼ã«ã«ã¦ã¼ã¶ã¨åã権éã奪åãããå±éºæ§ãããã¾ãã
ä»åããã®Windowsã®èå¼±æ§ï¼MS12-005ï¼ï¼CVE-2012-0013ï¼ã®åç¾æ§ã«ã¤ãã¦æ¤è¨¼ãè¡ãã¾ããã
Windows Packagerè¨å®ã«ãããä»»æã®ã³ã¼ããå®è¡å¯è½ãªèå¼±æ§(MS12-005)ï¼CVE-2012-0013ï¼ã«é¢ããæ¤è¨¼ã¬ãã¼ã
ãå½±é¿ãåããã¨ããã¦ããã¢ããªã±ã¼ã·ã§ã³ã
å½±é¿ãåããå¯è½æ§ãå ±åããã¦ããã®ã¯æ¬¡ã®éãã§ãã
- Windows XP Service Pack 3
- Windows XP Professional x64 Edition Service Pack 2
- Windows Server 2003 Service Pack 2
- Windows Server 2003 x64 Edition Service Pack 2
- Windows Server 2003 with SP2 for Itanium-based Systems
- Windows Vista Service Pack 2
- Windows Vista x64 Edition Service Pack 2
- Windows Server 2008 for 32-bit Systems Service Pack 2**
- Windows Server 2008 for x64-based Systems Service Pack 2**
- Windows Server 2008 for Itanium-based Systems Service Pack 2
- Windows 7 for 32-bit Systems ããã³ Windows 7 for 32-bit Systems Service Pack 1
- Windows 7 for x64-based Systems ããã³ Windows 7 for x64-based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based Systems ããã³ Windows Server 2008 R2 for x64-based Systems Service Pack 1**
- Windows Server 2008 R2 for Itanium-based Systems ããã³ Windows Server 2008 R2 for Itanium-based Systems Service Pack 1
ã**Server Coreã¤ã³ã¹ãã¼ã«ã§ã¯å½±é¿ãåãã¾ããã
ã対çæ¡ã
Microsoft社ããããã®èå¼±æ§ãä¿®æ£ããããã°ã©ã ï¼MS12-005ï¼ããªãªã¼ã¹ããã¦ãã¾ãã
å½è©²èå¼±æ§ãä¿®æ£ãããä¿®æ£ããã°ã©ã ãé©ç¨ãã¦ããã ããã¨ãæ¨å¥¨ãããã¾ãã
ãåèãµã¤ãã
CVE-2012-0013
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-0013
ãã¤ã¯ãã½ãã ã»ãã¥ãªãã£æ
å ± MS12-005 - éè¦
Microsoft Windows ã®èå¼±æ§ã«ããããªã¢ã¼ãã§ã³ã¼ããå®è¡ããã (2584146)
https://docs.microsoft.com/en-us/security-updates/SecurityBulletins/2012/ms12-005
JVNDB-2012-001048
è¤æ°ã® Microsoft Windows 製åã® Windows Packager è¨å®ã«ãããä»»æã®ã³ã¼ããå®è¡ãããèå¼±æ§
http://jvndb.jvn.jp/ja/contents/2012/JVNDB-2012-001048.html
ãæ¤è¨¼ã¤ã¡ã¼ã¸ã

ãæ¤è¨¼ã¿ã¼ã²ããã·ã¹ãã ã
Windows Vista
â»ç¢ºèªç¨ã«Windows 7
ãæ¤è¨¼æ¦è¦ã
ã¿ã¼ã²ããã·ã¹ãã ã§ç´°å·¥ãããWORDãã¡ã¤ã«ãéããããã¨ã§ä»»æã®ã³ã¼ããå®è¡ããã¾ãã
ä»åã®æ¤è¨¼ã¯ãã¿ã¼ã²ããã·ã¹ãã ä¸ã«ããã¯ãã¢ç¨ã®ã¦ã¼ã¶ï¼sugarfreeï¼ã追å ãããã®ã¦ã¼ã¶ãå©ç¨ãã¦ã·ã¹ãã å¶å¾¡ã奪åããã¨ãããã®ã§ãã
ããã«ããããªã¢ã¼ãããã¿ã¼ã²ããã·ã¹ãã ã®æä½ã奪åå¯è½ã¨ãªãã¾ãã
ãæ¤è¨¼çµæã
ä¸å³ã®èµ¤ç·ã§å²ã¾ãã¦ããé¨åã¯ã確èªç¨ã®ã³ã³ãã¥ã¼ã¿ãcheker7ï¼Windows 7ï¼ãä¸ã§ã®ã³ãã³ãå®è¡çµæã示ãã¦ãã¾ãã
é»ç·ã§å²ã¾ãã¦ããé¨åã¯ãã¿ã¼ã²ããã·ã¹ãã ã®ãã¹ãåãã¦ã¼ã¶ã¢ã«ã¦ã³ãæ
å ±ããããã¯ã¼ã¯ã¢ãã¬ã¹ã表示ããã¦ãã¾ãã
ããã«ãããã¿ã¼ã²ããã·ã¹ãã ã®å¶å¾¡ã®å¥ªåã«æåããã¨è¨ãã¾ãã

PDFçã®ãã¦ã³ãã¼ãã¯ãã¡ããããPDFç
â» åè¦æ ¼åãä¼ç¤¾åãå£ä½åã¯ãä¸è¬ã«å社ã®åæ¨ã¾ãã¯ç»é²åæ¨ã§ããTweet

ããååãå ã
NTTãã¼ã¿å 端æè¡æ ªå¼ä¼ç¤¾
ã»ãã¥ãªãã£äºæ¥é¨ãå¶æ¥æ
å½ãå¶æ¥ä¼ç»ã°ã«ã¼ã
TELï¼03-5425-1954