Windows 2000 suffers millennium bug Malicious code executio...

Próximas questões
Com base no mesmo assunto
Ano: 2005 Banca: FCC Órgão: TRE-RN
Q1201657 Inglês
Windows 2000 suffers millennium bug Malicious code execution possible thanks to flaw. Matthew Broersma, Techworld 22 April 2005 Microsoft has confirmed a security flaw in Windows 2000 that could allow attackers to execute malicious code via Windows Explorer and other programs. The flaw, involving a problem in the way the webvw.dll library validates document metadata, was disclosed earlier this week by security firm GreyMagic. The flaw could be exploited by distributing a malicious file which, when selected in Windows Explorer, could execute malicious script commands. More dangerously, an attacker could exploit the bug via a document on a remote SMB share, GreyMagic said. "Script commands that are injected in this manner will execute as soon as the malicious file is selected in Windows Explorer and will be executed in a trusted context, which means they will have the ability to perform any action the currently logged on user can perform," GreyMagic said in its advisory. "This includes reading, deleting and writing files, as well as executing arbitrary commands." Microsoft has confirmed that it is investigating the flaw, and as usual stated that it is not aware that any customers have been affected so far. The company has also criticised GreyMagic for posting proof-of-concept code along with its advisory. Stephen Toulouse of Microsoft's Security Response Center (MSRC), in a message posted on the Microsoft TechNet website, downplayed the danger posed by the flaw. "Significant user interaction would be required for an attacker to exploit this vulnerability," he wrote. Any attack would rely on Server Message Block (SMB) communication, which customers should block at the firewall level as a best practice, Toulouse said. No patch exists, but users can protect themselves by disabling the "Web view" option in Windows Explorer, Microsoft said. The company said it may patch the bug once its investigation is complete. The flaw affects Windows 2000 Professional, Server and Advanced Server versions, GreyMagic said. The affected library, webvw.dll, is used in displaying information in Windows Explorer's preview pane, which is enabled by default in Windows 2000 systems. An input-validation bug means an attacker could inject script commands into the "author" metadata field of a document, which could be executed when the metadata is processed by webvw.dll. Other applications using the library are also affected, GreyMagic said. "The malicious file does not need to be executed in order to activate the exploit, double-clicking is not required," the firm said in its advisory. "The exploitation takes place as soon as the file is selected." GreyMagic said it first notified Microsoft of the flaw on 18 January. (http://www.techworld.com/security/news/index.cfm?NewsID=3543)
No texto, downplayed significa
Alternativas

Gabarito comentado

Confira o gabarito comentado por um dos nossos professores

Vamos analisar a questão e compreender seu contexto:

A alternativa correta é a C - minimizou.

O termo "downplayed" no contexto apresentado significa "minimizou". Ou seja, Stephen Toulouse da Microsoft minimizou o perigo representado pela falha de segurança, afirmando que seria necessária uma interação significativa do usuário para que o ataque fosse bem-sucedido. Isso implica que ele tentou diminuir a percepção de seriedade do problema.

Agora, vamos justificar por que as outras alternativas estão incorretas:

A - exagerou: Esta alternativa está incorreta porque "downplayed" significa o oposto de exagerar. Toulouse não exagerou a ameaça; ele, na verdade, tentou diminuí-la.

B - enfatizou: Esta alternativa também está errada, já que enfatizar significa destacar a importância de algo. Toulouse, ao minimizar a ameaça, fez justamente o contrário de enfatizar.

D - abordou: Embora Toulouse tenha abordado o problema, o verbo "downplayed" não se refere a simplesmente abordar ou tratar do assunto. Ele se refere a tratar o assunto de maneira a reduzir sua importância.

E - criticou: Criticar significa apontar falhas ou fazer julgamentos negativos. No texto, Toulouse não está criticando a falha, mas sim minimizando a seriedade dela.

Gostou do comentário? Deixe sua avaliação aqui embaixo!

Clique para visualizar este gabarito

Visualize o gabarito desta questão clicando no botão abaixo

Comentários

Veja os comentários dos nossos alunos

gab.:c)minimizou

downplay: to make something seem less important or less bad than it really is

minimizar

The  has been  to downplay the .

Clique para visualizar este comentário

Visualize os comentários desta questão clicando no botão abaixo