[º¸¾È´º½º ±è°æ¾Ö] ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®(ÀÌÇÏ MS)ÀÇ Internet Explorer¿¡¼ ¿ø°ÝÄÚµå ½ÇÇàÀÌ °¡´ÉÇÑ ½Å±Ô Ãë¾àÁ¡ÀÌ ¹ß°ßµÅ »ç¿ëÀÚÀÇ ÁÖÀÇ°¡ ¿ä±¸µÈ´Ù. À̹ø¿¡ ¹ß°ßµÈ ½Å±Ô Ãë¾àÁ¡Àº º¸¾È ¾÷µ¥ÀÌÆ®°¡ ¾ÆÁ÷ ¹ßÇ¥µÇÁö ¾ÊÀº °ÍÀ¸·Î Ãë¾àÁ¡À» ¾Ç¿ëÇÑ °ø°Ý ½Ãµµ°¡ ÇØ¿Ü¿¡¼ È®ÀεƴÙ.
¡ã MSÀÇ º¸¾È ¾÷µ¥ÀÌÆ® ¹ßÇ¥ Àü±îÁö ¿µÇâÀ» ¹Þ´Â Internet Explorer ¹öÀüÀ» »ç¿ëÇÒ °æ¿ì »çÁø°ú °°ÀÌ MS¿¡¼ Á¦°øÇÏ´Â EMETÀ» Internet Explorer¿¡ Àû¿ëÇØ Ãë¾àÁ¡ÀÌ ¾Ç¿ëµÇÁö ¸øÇϵµ·Ï Á¶Ä¡ÇØ¾ß ÇÑ´Ù.
ÀÌ´Â Use-After-Free Ãë¾àÁ¡À» ÀÌ¿ëÇÑ ¿ø°ÝÄÚµå ½ÇÇà Ãë¾àÁ¡(CVE-2014-0322)À¸·Î, Use-After-Free´Â ÇÒ´ç ÇØÁ¦ÇÑ ¸Þ¸ð¸®¸¦ ´Ù½Ã ÂüÁ¶ÇÏ´Â °úÁ¤¿¡¼ ¹ß»ýÇÏ´Â Ãë¾àÁ¡ÀÌ´Ù.
¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î´Â Internet Explorer 9¿Í 10ÀÌ°í, ¿µÇâÀ» ¹ÞÁö ¾Ê´Â ¼ÒÇÁÆ®¿þ¾î´Â Internet Explorer 11ÀÌ´Ù.
ÀÌ¿Í °ü·Ã KISA ÀÎÅͳÝħÇØ´ëÀÀ¼¾ÅÍ´Â ¡°ÇØ´ç Ãë¾àÁ¡¿¡ ¿µÇâÀ» ¹ÞÁö ¾Ê´Â ¼ÒÇÁÆ®¿þ¾îÀÎ Internet Explorer 11À» »ç¿ëÇÏ°í, MSÀÇ º¸¾È ¾÷µ¥ÀÌÆ® ¹ßÇ¥ Àü±îÁö ¿µÇâÀ» ¹Þ´Â Internet Explorer ¹öÀüÀ» »ç¿ëÇÒ °æ¿ì Ãë¾àÁ¡¿¡ ÀÇÇÑ ÇÇÇظ¦ ÁÙÀ̱â À§ÇØ EMETÀ» »ç¿ëÇÒ °Í¡±À» ±ÇÀåÇß´Ù.
ÀÌ´Â EMET(Enhanced Mitigation Experience Toolkit)°¡ MS¿¡¼ Á¦°øÇÏ´Â ÇÁ·Î±×·¥À¸·Î ¼ÒÇÁÆ®¿þ¾îÀÇ Ãë¾àÁ¡ÀÌ ¾Ç¿ëµÇÁö ¸øÇϵµ·Ï ÇÏ´Â ±â´ÉÀ» ¼öÇàÇÑ´Ù.
ÀÌ¿¡ EMET(Enhanced Mitigation Experience Toolkit)À» Internet Explorer¿¡ Àû¿ëÇØ Ãë¾àÁ¡ÀÌ ¾Ç¿ëµÇÁö ¸øÇϵµ·Ï Á¶Ä¡ÇØ¾ß ÇÑ´Ù.
±âŸ ¹®ÀÇ»çÇ×Àº Çѱ¹ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® ÀüÈ 1577-9700°ú KISA ÀÎÅͳÝħÇØ´ëÀÀ¼¾ÅÍ¿¡ ±¹¹ø¾øÀÌ 118·Î ÇÏ¸é µÈ´Ù.
[Âü°í»çÀÌÆ®]
[1]http://www.fireeye.com/blog/uncategorized/2014/02/operation-snowman-deputydog-actor-compromises-us-veterans-of-foreign-wars-website.html
[2] http://support.microsoft.com/kb/2458544
[3] http://www.microsoft.com/en-us/download/confirmation.aspx?id=41138
[±è°æ¾Ö ±âÀÚ(boan3@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(http://www.boannews.com/) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>