Home / bulletins

MS10-009 - Critical: Vulnerabilities in Windows TCP/IP Could Allow Remote Code Execution (974145) - Version:1.1

Posted on 11 February 2010

Critical

Severity Rating: Critical - Revision Note: V1.1 (February 10, 2010): Corrected the command-line information for the Disable the "Core Networking - Router Advertisement (ICMPv6-In)" inbound firewall rule workaround. This is an informational change only.Summary: This security update resolves four privately reported vulnerabilities in Microsoft Windows. The most severe of these vulnerabilities could allow remote code execution if specially crafted packets are sent to a computer with IPv6 enabled. An attacker could try to exploit the vulnerability by creating specially crafted ICMPv6 packets and sending the packets to a system with IPv6 enabled. This vulnerability may only be exploited if the attacker is on-link.

Link

 

TOP