Home / bulletins

MS09-057 - Important: Vulnerability in Indexing Service Could Allow Remote Code Execution (969059) - Version:1.0

Posted on 14 October 2009

Important

Severity Rating: Important - Revision Note: Bulletin published.Summary: This security update resolves a privately reported vulnerability in Microsoft Windows. The vulnerability could allow remote code execution if an attacker set up a malicious Web page that invokes the Indexing Service through a call to its ActiveX component. This call could include a malicious URL and exploit the vulnerability, granting the attacker access to the client system with the privileges of the user browsing the Web page. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Link

 

TOP