Nortel Response to Microsoft Security Bulletin MS09-011
| Description: |
On Tuesday, April 14th, Microsoft released security update MS09-011 - Vulnerability in Microsoft DirectShow Could Allow Remote Code Execution (961373). This security update resolves a privately reported vulnerability in Microsoft DirectX. The vulnerability could allow remote code execution if user opened a specially crafted MJPEG file. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. MS09-011 addresses the following CVEs: 1) CVE-2009-0084 (http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-0084) A remote code execution vulnerability exists in the way Microsoft DirectShow handles supported format files. This vulnerability could allow code execution if a user opened a specially crafted MJPEG file. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. Please refer to the Microsoft link in the Source section for additional information about workarounds and mitigating factors for the vulnerabilities addressed by this update. Microsoft Ratings for MS09-011: Maximum Severity Rating - Critical Impact of Vulnerability - Remote Code Execution Exploitability Index - 2 - Inconsistent exploit code likely Bulletins Replaced by this Update - MS08-033. Before taking any action please ensure that you are viewing the latest official version of this security advisory by referencing http://www.nortel.com/securityadvisories For more information: Please contact your next level of support or visit http://www.nortel.com/co |
| Type: |
Security Advisories |
| Number: |
2009009449, Rev 1 |
| Status: |
Retired |
| Date: |
2009-11-02 |