PT-2008-4445 · Microsoft · Digital Image Suite+17

Publicado

2008-09-10

·

Atualizado

2018-10-30

·

CVE-2008-3014

CVSS v2.0

9.3

Alta

VetorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer 6 SP1 Windows XP SP2 and SP3 Server 2003 SP1 and SP2 Vista Gold and SP1 Server 2008 Office XP SP3 Office 2003 SP2 and SP3 2007 Microsoft Office System Gold and SP1 Visio 2002 SP2 PowerPoint Viewer 2003 Works 8 Digital Image Suite 2006 SQL Server 2000 Reporting Services SP2 SQL Server 2005 SP2 Report Viewer 2005 SP1 and 2008 Forefront Client Security 1.0
Description A remote code execution issue exists due to the way GDI+ allocates memory for WMF image files. This could allow remote code execution if a user opens a specially crafted WMF image file or browses to a Web site that contains specially crafted content. An attacker who successfully exploits this issue could take complete control of an affected system, then install programs, view, change, or delete data, or create new accounts with full user rights. Users with fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Recommendations As a temporary workaround, consider disabling the handling of WMF image files until a patch is available. Restrict access to Web sites that may contain specially crafted content to minimize the risk of exploitation. Avoid opening specially crafted WMF image files from untrusted sources until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Buffer Overflow

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2008-3014

Produtos afetados

2007 Microsoft Office System
Digital Image Suite
Forefront Client Security
Gdi+
Internet Explorer
Sql Server
Office
Office 2003
Office Visio
Office Xp
Powerpoint Viewer
Report Viewer
Server 2003
Server 2008
Vista
Windows
Windows Xp
Works