PT-2008-4445 · Microsoft · Digital Image Suite+17

Published

2008-09-10

·

Updated

2018-10-30

·

CVE-2008-3014

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Internet Explorer 6 SP1 Windows XP SP2 and SP3 Server 2003 SP1 and SP2 Vista Gold and SP1 Server 2008 Office XP SP3 Office 2003 SP2 and SP3 2007 Microsoft Office System Gold and SP1 Visio 2002 SP2 PowerPoint Viewer 2003 Works 8 Digital Image Suite 2006 SQL Server 2000 Reporting Services SP2 SQL Server 2005 SP2 Report Viewer 2005 SP1 and 2008 Forefront Client Security 1.0
Description A remote code execution issue exists due to the way GDI+ allocates memory for WMF image files. This could allow remote code execution if a user opens a specially crafted WMF image file or browses to a Web site that contains specially crafted content. An attacker who successfully exploits this issue could take complete control of an affected system, then install programs, view, change, or delete data, or create new accounts with full user rights. Users with fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Recommendations As a temporary workaround, consider disabling the handling of WMF image files until a patch is available. Restrict access to Web sites that may contain specially crafted content to minimize the risk of exploitation. Avoid opening specially crafted WMF image files from untrusted sources until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-3014

Affected Products

2007 Microsoft Office System
Digital Image Suite
Forefront Client Security
Gdi+
Internet Explorer
Sql Server
Office
Office 2003
Office Visio
Office Xp
Powerpoint Viewer
Report Viewer
Server 2003
Server 2008
Vista
Windows
Windows Xp
Works