{"id":791,"date":"2012-10-11T11:20:17","date_gmt":"2012-10-11T03:20:17","guid":{"rendered":"http:\/\/down.cdhaha.net\/?p=791"},"modified":"2012-12-13T15:07:50","modified_gmt":"2012-12-13T07:07:50","slug":"ms12-066-vulnerability-in-html-sanitization-component-could-allow-elevation-of-privilege-2741517","status":"publish","type":"post","link":"http:\/\/down.cdhaha.net\/?p=791","title":{"rendered":"MS12-066 Vulnerability in HTML Sanitization Component Could Allow Elevation of Privilege (2741517)"},"content":{"rendered":"<p><img decoding=\"async\" src=\"wp-content\/uploads\/2009\/09\/html.gif\" alt=\"HTML Component\" title=\"HTML Component\" class=\"alignleft\" \/>\u6b64\u5b89\u5168\u66f4\u65b0\u53ef\u89e3\u51b3 Microsoft Office\u3001Microsoft Communications Platforms\u3001Microsoft Server \u8f6f\u4ef6\u548c Microsoft Office Web Apps \u4e2d\u4e00\u4e2a\u516c\u5f00\u62ab\u9732\u7684\u6f0f\u6d1e\u3002\u5982\u679c\u653b\u51fb\u8005\u5c06\u7279\u5236\u5185\u5bb9\u53d1\u9001\u7ed9\u7528\u6237\uff0c\u5219\u8be5\u6f0f\u6d1e\u53ef\u80fd\u5141\u8bb8\u7279\u6743\u63d0\u5347\u3002<\/p>\n<p>\u5bf9\u4e8e <strong>Microsoft InfoPath 2007\u3001Microsoft InfoPath 2010\u3001Microsoft Communicator 2007 R2\u3001Microsoft Lync 2010\u3001Microsoft Lync 2010 Attendee\u3001Microsoft SharePoint Server 2007\u3001Microsoft SharePoint Server 2010\u3001Microsoft Groove Server 2010\u3001Microsoft SharePoint Windows Services 3.0\u3001Microsoft SharePoint Foundation 2010 \u548c Microsoft Office Web Apps 2010 <\/strong>\u7684\u53d7\u652f\u6301\u7248\u672c\uff0c\u6b64\u5b89\u5168\u66f4\u65b0\u7684\u7b49\u7ea7\u4e3a\u201c\u91cd\u8981\u201d\u3002\u6b64\u5b89\u5168\u66f4\u65b0\u901a\u8fc7\u4fee\u6539\u6e05\u7406 HTML \u5b57\u7b26\u4e32\u7684\u65b9\u5f0f\u6765\u89e3\u51b3\u6f0f\u6d1e\u3002<br \/>\n<!--more--><\/p>\n<p>\u5efa\u8bae\u3002 \u5ba2\u6237\u53ef\u4ee5\u914d\u7f6e\u81ea\u52a8\u66f4\u65b0\uff0c\u4ee5\u4f7f\u7528 Microsoft Update \u670d\u52a1\u4ece Microsoft Update \u8054\u673a\u68c0\u67e5\u66f4\u65b0\u3002\u542f\u7528\u4e86\u81ea\u52a8\u66f4\u65b0\u4e14\u914d\u7f6e\u4e3a\u4ece Microsoft Update \u8054\u673a\u68c0\u67e5\u66f4\u65b0\u7684\u5ba2\u6237\u901a\u5e38\u4e0d\u9700\u8981\u6267\u884c\u4efb\u4f55\u64cd\u4f5c\uff0c\u56e0\u4e3a\u6b64\u5b89\u5168\u66f4\u65b0\u5c06\u81ea\u52a8\u4e0b\u8f7d\u548c\u5b89\u88c5\u3002\u5c1a\u672a\u542f\u7528\u81ea\u52a8\u66f4\u65b0\u7684\u5ba2\u6237\u9700\u8981\u4ece Microsoft Update \u68c0\u67e5\u66f4\u65b0\uff0c\u5e76\u624b\u52a8\u5b89\u88c5\u6b64\u66f4\u65b0\u3002\u6709\u5173 Windows XP \u548c Windows Server 2003 \u53d7\u652f\u6301\u7248\u672c\u4e2d\u81ea\u52a8\u66f4\u65b0\u4e2d\u7684\u7279\u5b9a\u914d\u7f6e\u9009\u9879\u7684\u4fe1\u606f\uff0c\u8bf7\u53c2\u9605 Microsoft \u77e5\u8bc6\u5e93\u6587\u7ae0 294871\u3002\u6709\u5173 Windows Vista\u3001Windows Server 2008\u3001Windows 7 \u548c Windows Server 2008 R2 \u7684\u53d7\u652f\u6301\u7248\u672c\u4e2d\u81ea\u52a8\u66f4\u65b0\u7684\u4fe1\u606f\uff0c\u8bf7\u53c2\u9605\u4e86\u89e3 Windows \u81ea\u52a8\u66f4\u65b0\u3002<\/p>\n<p>\u5bf9\u4e8e\u7ba1\u7406\u5458\u3001\u4f01\u4e1a\u5b89\u88c5\u6216\u8005\u60f3\u8981\u624b\u52a8\u5b89\u88c5\u6b64\u5b89\u5168\u66f4\u65b0\u7684\u6700\u7ec8\u7528\u6237\uff0cMicrosoft \u5efa\u8bae\u5ba2\u6237\u4f7f\u7528\u66f4\u65b0\u7ba1\u7406\u8f6f\u4ef6\u5c3d\u65e9\u5e94\u7528\u6b64\u66f4\u65b0\u6216\u8005\u5229\u7528 Microsoft Update \u670d\u52a1\u68c0\u67e5\u66f4\u65b0\u3002<\/p>\n<p>\u53e6\u8bf7\u53c2\u9605\u672c\u516c\u544a\u540e\u9762\u90e8\u5206\u4e2d\u7684\u201c\u68c0\u6d4b\u548c\u90e8\u7f72\u5de5\u5177\u53ca\u6307\u5bfc\u201d\u4e00\u8282\u3002<\/p>\n<p>\u5df2\u77e5\u95ee\u9898\u3002 Microsoft \u77e5\u8bc6\u5e93\u6587\u7ae0 2741517 \u4ecb\u7ecd\u4e86\u5ba2\u6237\u5728\u5b89\u88c5\u6b64\u5b89\u5168\u66f4\u65b0\u65f6\u53ef\u80fd\u9047\u5230\u7684\u5f53\u524d\u5df2\u77e5\u95ee\u9898\u3002\u672c\u6587\u8fd8\u4ecb\u7ecd\u4e86\u8fd9\u4e9b\u95ee\u9898\u7684\u5efa\u8bae\u89e3\u51b3\u529e\u6cd5\u3002\u5728\u5f53\u524d\u5df2\u77e5\u95ee\u9898\u548c\u5efa\u8bae\u89e3\u51b3\u529e\u6cd5\u4ec5\u9002\u7528\u4e8e\u6b64\u8f6f\u4ef6\u7684\u7279\u5b9a\u7248\u672c\u65f6\uff0c\u6b64\u6587\u7ae0\u8fd8\u63d0\u4f9b\u5176\u4ed6\u6587\u7ae0\u7684\u94fe\u63a5\u3002<\/p>\n<p><strong>English Version<\/strong><br \/>\n<a href=\"http:\/\/technet.microsoft.com\/en-us\/security\/bulletin\/MS12-066\" target=\"_blank\">http:\/\/technet.microsoft.com\/en-us\/security\/bulletin\/MS12-066<\/a><\/p>\n<p><strong>\u7b80\u4f53\u4e2d\u6587\u7248<\/strong><br \/>\n<a href=\"http:\/\/technet.microsoft.com\/zh-cn\/security\/bulletin\/MS12-066\" target=\"_blank\">http:\/\/technet.microsoft.com\/zh-cn\/security\/bulletin\/MS12-066<\/a><\/p>\n<p>&nbsp;<\/p>\n<!-- AddThis Advanced Settings generic via filter on the_content --><!-- AddThis Share Buttons generic via filter on the_content -->","protected":false},"excerpt":{"rendered":"<p>\u6b64\u5b89\u5168\u66f4\u65b0\u53ef\u89e3\u51b3 Microsoft Office\u3001Microsoft Communications Platforms\u3001Microsoft Server \u8f6f\u4ef6\u548c Microsoft Office Web Apps \u4e2d\u4e00\u4e2a\u516c\u5f00\u62ab\u9732\u7684\u6f0f\u6d1e\u3002\u5982\u679c\u653b\u51fb\u8005\u5c06\u7279\u5236\u5185\u5bb9\u53d1\u9001\u7ed9\u7528\u6237\uff0c\u5219\u8be5\u6f0f\u6d1e\u53ef\u80fd\u5141\u8bb8\u7279\u6743\u63d0\u5347\u3002 \u5bf9\u4e8e Microsoft InfoPath 2007\u3001Microsoft InfoPath 2010\u3001Microsoft Communicator 2007&#8230;<!-- AddThis Advanced Settings generic via filter on get_the_excerpt --><!-- AddThis Share Buttons generic via filter on get_the_excerpt --><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[895],"tags":[939,940],"_links":{"self":[{"href":"http:\/\/down.cdhaha.net\/index.php?rest_route=\/wp\/v2\/posts\/791"}],"collection":[{"href":"http:\/\/down.cdhaha.net\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/down.cdhaha.net\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/down.cdhaha.net\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/down.cdhaha.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=791"}],"version-history":[{"count":0,"href":"http:\/\/down.cdhaha.net\/index.php?rest_route=\/wp\/v2\/posts\/791\/revisions"}],"wp:attachment":[{"href":"http:\/\/down.cdhaha.net\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=791"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/down.cdhaha.net\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=791"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/down.cdhaha.net\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=791"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}