PT-2008-4445 · Microsoft · Digital Image Suite+17
Published
2008-09-10
·
Updated
2018-10-30
·
CVE-2008-3014
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Internet Explorer 6 SP1
Windows XP SP2 and SP3
Server 2003 SP1 and SP2
Vista Gold and SP1
Server 2008
Office XP SP3
Office 2003 SP2 and SP3
2007 Microsoft Office System Gold and SP1
Visio 2002 SP2
PowerPoint Viewer 2003
Works 8
Digital Image Suite 2006
SQL Server 2000 Reporting Services SP2
SQL Server 2005 SP2
Report Viewer 2005 SP1 and 2008
Forefront Client Security 1.0
Description
A remote code execution issue exists due to the way GDI+ allocates memory for WMF image files. This could allow remote code execution if a user opens a specially crafted WMF image file or browses to a Web site that contains specially crafted content. An attacker who successfully exploits this issue could take complete control of an affected system, then install programs, view, change, or delete data, or create new accounts with full user rights. Users with fewer user rights on the system could be less impacted than users who operate with administrative user rights.
Recommendations
As a temporary workaround, consider disabling the handling of WMF image files until a patch is available.
Restrict access to Web sites that may contain specially crafted content to minimize the risk of exploitation.
Avoid opening specially crafted WMF image files from untrusted sources until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
2007 Microsoft Office System
Digital Image Suite
Forefront Client Security
Gdi+
Internet Explorer
Sql Server
Office
Office 2003
Office Visio
Office Xp
Powerpoint Viewer
Report Viewer
Server 2003
Server 2008
Vista
Windows
Windows Xp
Works