

| ¹øÈ£ | µî·ÏÀÏ | Á¦¸ñ | ||
|---|---|---|---|---|
| 33 | 2010.01.22 | MS À©µµ¿ì Ä¿³Î ±ÇÇÑ»ó½Â Ãë¾àÁ¡ ÁÖÀÇ (CVE-2010-0232) |

1. ¼³¸í
·¹°Å½Ã 16ºñÆ® ÀÀ¿ë ÇÁ·Î±×·¥¿¡¼ »ç¿ëÇÏ´Â BIOS ¼ºñ½º ·çƾÀ» Áö¿øÇÏ´Â °¡»ó 8086 ¸ðµå ±¸Çö¿¡¼ ·ÎÄà ±ÇÇÑ »ó½ÂÀÌ °¡´ÉÇÑ Ãë¾àÁ¡ÀÌ ¹ß°ßµÇ¾ú½À´Ï´Ù. À©µµ¿ì NT 3.1ºÎÅÍ Áö±ÝÀÇ À©µµ¿ì 7¿¡ À̸£±â±îÁö ¸ðµç 32ºñÆ® ¹öÀüÀÇ À©µµ¿ì°¡ Ãë¾àÇÕ´Ï´Ù.
- À©µµ¿ì Ä¿³ÎÀÌ VDMÀ» ½ÇÇàÇÒ ¶§ ƯÁ¤ ¿¹¿Ü¸¦ ÀûÀýÇÏÁö ¾Ê°Ô ó¸®ÇÏ¿© ±ÇÇÑ»ó½Â Ãë¾àÁ¡ÀÌ ¹ß»ý ÇÕ´Ï´Ù.
- À¯È¿ÇÑ ·ÎÄà »ç¿ëÀÚ ±ÇÇÑÀ» °¡Áø °ø°ÝÀÚ´Â Ãë¾àÁ¡À» ÀÌ¿ëÇØ Ä¿³Î ¸ðµå¿¡¼ ÀÓÀÇÀÇ Äڵ带 ½ÇÇà ÇÒ ¼ö ÀÖ°í
¿µÇâ ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇØ ¿ÏÀüÇÑ ±ÇÇÑÀ» ȹµæÇÒ ¼ö ÀÖ½À´Ï´Ù.
- ÇØ´ç Ãë¾àÁ¡ÀÌ °ø°³µÇ¾úÀ¸¹Ç·Î ±ÇÇÑ °ü¸®°¡ ÇÊ¿äÇÑ ½Ã½ºÅÛÀÇ °ü¸®ÀÚ´Â °¢º°ÇÑ ÁÖÀǰ¡ ¿ä±¸µË´Ï´Ù.
¡Ø À©µµ¿ì Ä¿³Î : ÀåÄ¡ °ü¸®, ¸Þ¸ð¸® °ü¸®, ÇÁ·Î¼¼¼ ½ºÄÉÁÙ¸µ µî ½Ã½ºÅÛ ¼öÁØÀÇ ¼ºñ½º¸¦ Á¦°øÇÏ´Â ¿î¿µÃ¼Á¦ÀÇ ÇÙ½É
¡Ø VDM (Virtual DOS Machine) : MS À©µµ¿ì NT ±â¹ÝÀÇ ¿î¿µÃ¼Á¦ ³»¿¡¼ MS-DOS¿Í
16ºñÆ® À©µµ¿ì¸¦ ¿¡¹Ä·¹ÀÌÆ®ÇÏ´Â °¡»óÀÇ ¼ºê½Ã½ºÅÛ
2. ¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î [1]
- Microsoft Windows 2000 SP4 for 32-bit Systems
- Windows XP SP2, SP3 for 32-bit Systems
- Windows Server 2003 SP2 for 32-bit Systems
- Windows Vista, SP1, SP2 for 32-bit Systems
- Windows Server 2008 for 32-bit Systems, SP2
- Windows 7 for 32-bit Systems
¿µÇâ ¹ÞÁö ¾Ê´Â ¼ÒÇÁÆ®¿þ¾î [1]
- Windows XP Professional x64 Edition SP2
- Windows Server 2003 x64 Edition SP2
- Windows Server 2003 with SP2 for Itanium-based Systems
- Windows Vista x64 Edition, SP1, SP2
- Windows Server 2008 for x64-based Systems, SP2
- Windows Server 2008 for Itanium-based Systems, SP2
- Windows 7 for x64-based Systems
- Windows Server 2008 R2 for x64-based Systems
- Windows Server 2008 R2 for Itanium-based Systems
3. ÀÓ½Ã ÇØ°á ¹æ¾È
- ÇöÀç ÇØ´ç Ãë¾àÁ¡¿¡ ´ëÇÑ º¸¾È¾÷µ¥ÀÌÆ®´Â ¹ßÇ¥µÇÁö ¾Ê¾Ò½À´Ï´Ù.
- 16ºñÆ® ÀÀ¿ë ÇÁ·Î±×·¥À» ½ÇÇàÇÒ ¼ö ¾øµµ·Ï Á¤Ã¥À» ¹Ù²Ù¸é Ãë¾àÁ¡À» ºÀ¼âÇÒ ¼ö ÀÖ½À´Ï´Ù.
- NTVDM ¼ºê½Ã½ºÅÛÀ» ºñȰ¼ºÈ [1, 2]
- "±×·ì Á¤Ã¥" ÄܼÖÀ» ½ÇÇà : ½ÃÀÛ¡æ½ÇÇà¡ægpedit.mscÀ» ÀÔ·Â ÈÄ È®Àιöư Ŭ¸¯
- "±×·ì Á¤Ã¥" Äֿܼ¡¼ "°ü¸® ÅÛÇø´"¡æ"Windows ±¸¼º ¿ä¼Ò"¡æ"ÀÀ¿ë ÇÁ·Î±×·¥ ȣȯ¼º"ÀÇ ¼ø¼·Î
Æú´õ¸¦ È®Àå
- "16ºñÆ® ÀÀ¿ë ÇÁ·Î±×·¥À¸·ÎÀÇ ¾×¼¼½º¸¦ ±ÝÁö"¸¦ Ŭ¸¯ÇÏ¿© "»ç¿ë"À¸·Î ¼³Á¤ º¯°æ
¡Ø ¼³Á¤À» Àû¿ëÇϸé 16ºñÆ® MS-DOS ¶Ç´Â À©µµ¿ì 3.1 ÀÀ¿ë ÇÁ·Î±×·¥À» »ç¿ëÇÒ ¼ö ¾øÀ¸¹Ç·Î
ÁÖÀÇ ÇÏ¿©¾ß ÇÕ´Ï´Ù.[1, 2]
- MS º¸¾È¾÷µ¥ÀÌÆ® »çÀÌÆ®¸¦ ÁÖ±âÀûÀ¸·Î È®ÀÎÇÏ¿© ÇØ´ç Ãë¾àÁ¡¿¡ ´ëÇÑ º¸¾È¾÷µ¥ÀÌÆ® ¹ßÇ¥ ½Ã ½Å¼ÓÈ÷
Ãֽо÷µ¥ÀÌÆ®¸¦ Àû¿ëÇϰųª ÀÚµ¿¾÷µ¥ÀÌÆ®¸¦ ¼³Á¤À» ±Ç°í ÇÕ´Ï´Ù.
¡Ø ÀÚµ¿¾÷µ¥ÀÌÆ® ¼³Á¤ ¹æ¹ý: ½ÃÀÛ¡æÁ¦¾îÆÇ¡æº¸¾È¼¾ÅÍ¡æÀÚµ¿¾÷µ¥ÀÌÆ®¡æÀÚµ¿(±ÇÀå) ¼±ÅÃ
- ´ÙÀ½ µ¿¿µ»óÀ» Âü°í ÇϽʽÿä.
¡Ø[µ¿¿µ»ó] À©µµ¿ì ¼¹ö 2003 µµ¸ÞÀÎ ÄÁÆ®·Ñ·¯¿¡¼ Á¤Ã¥ º¯°æÇÏ´Â ¹æ¹ý
¡Ø[µ¿¿µ»ó] À©µµ¿ì ¼¹ö 2008 µµ¸ÞÀÎ ÄÁÆ®·Ñ·¯¿¡¼ Á¤Ã¥ º¯°æÇÏ´Â ¹æ¹ý
¡Ø[µ¿¿µ»ó] À©µµ¿ì XP¿¡¼ Á¤Ã¥ º¯°æÇÏ´Â ¹æ¹ý
4. Âü°í»çÀÌÆ®
[1] http://www.microsoft.com/technet/security/advisory/979682.mspx
[2] http://www.vupen.com/english/advisories/2010/0179
[3] http://seclists.org/fulldisclosure/2010/Jan/341
[4] http://update.microsoft.com/microsoftupdate/v6/default.aspx?ln=ko


