PT-2007-2634 · Microsoft · Windows 2000+4
Published
2007-04-04
·
Updated
2018-10-16
·
CVE-2007-1212
CVSS v2.0
6.6
Medium
| Vector | AV:L/AC:M/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions 2000 SP4 through Vista
Description
The issue concerns an elevation of privilege vulnerability in the rendering of Enhanced Metafile (EMF) image format files. Any program that renders EMF images on the affected systems could be vulnerable to this attack. An attacker who successfully exploited this vulnerability could take complete control of an affected system.
Recommendations
For Microsoft Windows 2000 SP4, update to a version that includes the fix for this issue.
For Microsoft Windows XP SP2, update to a version that includes the fix for this issue.
For Microsoft Windows Server 2003 Gold, SP1, and SP2, update to a version that includes the fix for this issue.
For Microsoft Windows Vista, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting the rendering of EMF images on affected systems until a patch is available.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows
Windows 2000
Windows Server 2003
Windows Vista
Windows Xp