PT-2014-1672 · Microsoft · Windows Rt+16
Ben Hawkes
+2
·
Published
2014-06-10
·
Updated
2019-05-17
·
CVE-2014-1818
CVSS v2.0
9.3
High
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
GDI+ in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1
Office 2007 SP3 and 2010 SP1 and SP2
Live Meeting 2007 Console
Lync 2010 and 2013
Lync 2010 Attendee
Lync Basic 2013
Description
A remote code execution issue exists in the way GDI+ handles validation of specially crafted images. The issue could allow remote code execution if a user opens a specially crafted image. An attacker who successfully exploits this issue could take complete control of an affected system, then install programs, view, change, or delete data, or create new accounts with full user rights. Users with limited system rights are less impacted than those operating with administrative user rights.
Recommendations
For Microsoft Windows Server 2003 SP2, update to a newer version to mitigate the risk.
For Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, update to a newer version to mitigate the risk.
For Office 2007 SP3 and 2010 SP1 and SP2, update to a newer version to mitigate the risk.
For Live Meeting 2007 Console, Lync 2010 and 2013, Lync 2010 Attendee, and Lync Basic 2013, update to a newer version to mitigate the risk.
As a temporary workaround, consider restricting the use of GDI+ until a patch is available.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Gdi+
Live Meeting 2007
Lync 2010
Lync 2013
Lync Basic 2013
Office
Office 2007
Office 2010
Windows
Windows 7
Windows 8
Windows 8.1
Windows Rt
Windows Server 2003
Windows Server 2008
Windows Server 2012
Windows Vista