A security vulnerability exists in $(PACKAGE.PRODUCTNAME) that could allow arbitrary code to run when a maliciously modified file is opened. This update resolves that vulnerability.
However, an attacker could, in turn, exploit these vulnerabilities to cause the arbitrary code to run at a medium integrity level (permissions of the current user).
For example, an attacker could exploit another vulnerability to run arbitrary code through Internet Explorer. An attacker could then, in turn, exploit this vulnerability to cause the arbitrary code to run at a medium integrity level (permissions of the current user).
If an attacker inputs an overly long username, a buffer overflow will occur and it allows the attacker to run arbitrary code in the web server's security context.
如果攻击者输入很长的用户名,将造成缓冲区溢出,这会允许攻击者在 Web 服务器的安全上下文中执行任意代码。
Successful exploits will allow an attacker to run arbitrary code in the context of the user running the application. Failed attacks may cause denial-of-service conditions.
However, an attacker could use the ASLR bypass vulnerability in conjunction with another vulnerability, such as a remote code execution vulnerability, to run arbitrary code.
Instead, an attacker would have to convince users to take action. For example, an attacker could exploit another vulnerability to run arbitrary code through Internet Explorer.
However, an attacker could use this ASLR bypass vulnerability in conjunction with another vulnerability, such as a remote code execution vulnerability that could take advantage of the ASLR bypass to run arbitrary code.
For example, an attacker could exploit another vulnerability to run arbitrary code through Internet Explorer, but due to the context in which processes are launched by Internet Explorer, the code might be restricted to run at a low integrity level (very limited permissions).
例如,攻击者可以利用另一个漏洞以通过 Internet Explorer 运行任意代码,但是由于 Internet Explorer 启动的进程的上下文,代码可能被限制为在较低的完整性级别(权限非常有限)运行。
However, an attacker could use this ASLR bypass vulnerability in conjunction with another vulnerability, such as a remote code execution vulnerability that could take advantage of the ASLR bypass to run arbitrary code.
然而,攻击者可以结合其他漏洞使用此漏洞绕过地址空间布局随机化 (ASLR) 等安全功能。
An attacker who successfully exploited this vulnerability could run arbitrary code in kernel mode.
成功利用此漏洞的攻击者可以在系统帐户的上下文中执行任意代码。
Conteúdo potencialmente sensível ou impróprio
Os exemplos servem apenas como ajuda na tradução da palavra ou da expressão procurada. Eles não são selecionados ou validados por nós e podem conter linguagem inapropriada. Pedimos que reporte exemplos que devem ser modificados ou que não devem ser exibidos. As traduções potencialmente sensivéis, impróprias ou coloquiais geralmente são marcadas em vermelho ou em laranja.