
05-11-2011
|
 |
Moderator
|
|
Join Date: Sep 2006
Location: Emerald Isle
Posts: 82,973
Thanks: 24
Thanked 176 Times in 46 Posts
|
|
|
MS11-025 - Important: Vulnerability in Microsoft Foundation Class (MFC) Library Could Allow Remote Code Execution (2500212) - Version:2.1
Severity Rating: Important - Revision Note: V2.1 (April 27, 2011): Corrected the bulletin replacement information and clarified the update FAQ entry, "Will I be offered this update even if I have no suitable attack vectors on my system?"Summary: This security update resolves a publicly disclosed vulnerability in certain applications built using the Microsoft Foundation Class (MFC) Library. The vulnerability could allow remote code execution if a user opens a legitimate file associated with such an affected application, and the file is located in the same network folder as a specially crafted library file. For an attack to be successful, a user must visit an untrusted remote file system location or WebDAV share and open a document from this location that is then loaded by the affected application.
More...
|