¾ÇÀÇÀûÀÎ ÆÄ¿öÆ÷ÀÎÆ®ÀÇ Á¦·Îµ¥ÀÌ Ãë¾àÁ¡, »çÀ̹ö¹üÁË¿¡ ¾Ç¿ë
½ÇÁ¦ ÇÇÇØÀÚ ¸¹Áö ¾Ê¾Æ °ø°ÝÂ÷´ÜÇÏ´Â ÇȽºÀÕ(Fixit) Åø¸¸ Á¦°ø
[º¸¾È´º½º ¹Î¼¼¾Æ] ¾ó¸¶ Àü ·¯½Ã¾ÆÀÇ »çÀ̹ö ½ºÆÄÀÌ ¹× ¹üÁË ÇàÀ§¿¡ ÆÄ¿öÆ÷ÀÎÆ® ÇÁ·¹Á¨Å×ÀÌ¼Ç ÆÄÀÏÀÌ È°¿ëµÈ °ÍÀ¸·Î µå·¯³ °¡¿îµ¥ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®´Â 10¿ù 21ÀÏ À̸ÞÀÏ Ã·ºÎÆÄÀÏ·Î º¸³»Áø ¾ÇÀÇÀûÀÎ ÆÄ¿öÆ÷ÀÎÆ®ÀÇ Á¦·Îµ¥ÀÌ Ãë¾àÁ¡ÀÌ »çÀ̹ö ¹üÁË¿¡ ¾Ç¿ëµÇ°í ÀÖ´Ù°í À©µµ¿ì »ç¿ëÀڵ鿡°Ô °æ°íÇß´Ù.
À̹ø °áÇÔÀº ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®¿¡¼ ÀÚü °æ°í¸¦ ºÙÀÌÁö ¾Ê¾ÒÁö¸¸ ÇØÄ¿µéÀÌ »ç¿ëÀÚ PCÀÇ Á¤º¸¸¦ ÈÉÄ¡°Å³ª ´Ù¸¥ ¾Ç¼ºÄڵ带 ½É´Â µîÀÇ °ø°ÝÇàÀ§¸¦ ÇÒ ¼ö ÀÖ´Â ÀͽºÇ÷ÎÀÕÀ¸·Î ÆǸíµÆ´Ù.
Windows 2003À» Á¦¿ÜÇÑ ¸ðµç ¹öÀüÀÇ Windows¿Í OLE(Object Linking and Embedding)°´Ã¼¸¦ Á¶Á¤ÇÏ´Â ¿î¿µÃ¼Á¦ Äڵ忡 ¿µÇâÀ» ³¢Ä£´Ù.
ÆÄ¿öÆ÷ÀÎÆ®¸¦ ÅëÇÑ °ø°ÝÀ¸·Î ÇÑÁ¤ÀûÀÌ°í Ç¥ÀûÈµÈ °ø°ÝÀÌÁö¸¸, ´Ù¸¥ ¿ÀÇǽº ÆÄÀÏ¿¡¼µµ ¾Ç¿ëµÉ ¼ö ÀÖ´Ù°í ÁÖÀÇÇß´Ù.
Áö±Ý±îÁö °ø°ÝÀÌ ³Î¸® È®»êµÇÁö ¾Ê°í, ½ÇÁ¦ ÇÇÇظ¦ ÀÔÀº °í°´ÀÌ ¸¹Áö ¾Ê¾Æ ºñ»ó ¾÷µ¥ÀÌÆ®´Â ÇÏÁö ¾Ê°í ÇȽºÀÕ(Fixit) Åø Á¦°ø¸¸À¸·Î °ø°Ý Â÷´ÜÀ» ±Ç°íÇÏ°í ÀÖ´Ù.
ÀÌ¿Í °ü·Ã, º¸´Ù ÀÚ¼¼ÇÑ »çÇ×Àº Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝħÇØ´ëÀÀ¼¾ÅÍ È¨ÆäÀÌÁö³ª ¾Æ·¡ÀÇ Ãâó¸¦ Âü°íÇÏ¸é µÈ´Ù.
[Ãâó]
1.http://www.theregister.co.uk/2014/10/22/powerpoint_attacks_exploit_ms_0day/
2.http://blog.trendmicro.com/trendlabs-security-intelligence/microsoft-windows-hit-by-new-zero-day-attack/
3.http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-6352
4.https://technet.microsoft.com/library/security/3010060
[¹Î¼¼¾Æ ±âÀÚ(boan5@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(http://www.boannews.com/) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>