[內容說明:]
轉發國家資通安全會報 技術服務中心 漏洞/資安訊息警訊 ICST-ANA-2015-0004
微軟發布 HTTP.sys可能會允許遠端執行程式碼之資訊安全更新,美國國家標準技術研究所(NIST)的國家弱點資料庫(NVD)發布弱點編號 CVE-2015-1635 [1-2]。
HTTP.sys為處理 HTTP要求的核心模式趨動程式,允許遠端使用者利用 Request Header 未檢查 Range 參數範圍漏洞,進行攻擊行為;成功利用這個資訊安全風險的攻擊者,能以系統帳戶權限層級執行任意程式碼或阻斷服務攻擊(DoS)。
詳情請參閱附件
link to https://accounts.google.com/v3/signin/identifier?continue=https%3A%2F%2Fclassroom.google.com&ifkv=ARpgrqfChTdXHLzfzfh2SJdrTbiAOFUCUFykbows29iN_4jB_UoUkez_eXtUX0bSib2ZZWcC-RlFxg&passive=true&flowName=GlifWebSignIn&flowEntry=ServiceLogin&dsh=S-872127971%3A1726710420974973&ddm=0link to https://accounts.google.com/InteractiveLogin/signinchooser?continue=https%3A%2F%2Fclassroom.google.com%2Fu%2F0%2F&emr=1&followup=https%3A%2F%2Fclassroom.google.com%2Fu%2F0%2F&passive=1209600&service=classroom&ifkv=ARpgrqeD2pbsniIMA8nM_6NZbxeo_eNh7x6BJi03v6UU6r3pkfAgXzjRtpyEhL_q0Qm_Y82z_PrWIw&ddm=0&flowName=GlifWebSignIn&flowEntry=ServiceLogin
link to http://course.tn.edu.tw/school.aspx?sch=114785&year=113 \_blank link to https://www.hwces.tn.edu.tw/uploads/tad_blocks/file/113%E5%AD%B8%E5%B9%B4%E5%BA%A6%E6%95%99%E7%A7%91%E6%9B%B8%E9%81%B8%E7%94%A8%E7%89%88%E6%9C%AC.pdf onclick=window.open(this.href, , resizable=yes,status=no,location=no,toolbar=no,menubar=no,fullscreen=no,scrollbars=yes,dependent=no); return false;link to https://www.tainan.gov.tw/cp.aspx?n=34371 _blanklink to https://www.hwces.tn.edu.tw/uploads/tad_blocks/file/113%E5%AD%B8%E5%B9%B4%E5%BA%A6%E6%95%99%E7%A7%91%E6%9B%B8%E9%81%B8%E7%94%A8%E7%89%88%E6%9C%AC.pdf onclick=window.open(this.href, , resizable=yes,status=no,location=no,toolbar=no,menubar=no,fullscreen=no,scrollbars=yes,dependent=no); return