Microsoft GDI+ Remote Code Execution Vulnerability
RISK: Medium Risk
TYPE: Operating Systems - Windows OS
A remote code execution vulnerability exists in the way that affected Windows components and other affected software handle specially crafted TrueType font files. The vulnerability could allow remote code execution if a user views shared content that embeds TrueType font files. An attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full administrative rights.
Impact
- Remote Code Execution
System / Technologies affected
- Windows XP
- Windows Server 2003
- Windows Vista
- Windows Server 2008
- Windows 7
- Windows Server 2008 R2
- Windows 8
- Windows Server 2012
- Windows RT
- Microsoft Office 2003
- Microsoft Office 2007
- Microsoft Office 2010
- Microsoft Visual Studio .NET 2003
- Microsoft Lync 2010
- Microsoft Lync 2013
- Microsoft Lync Basic 2013
Solutions
- Download location for patches:
http://technet.microsoft.com/en-us/security/bulletin/MS13-054
Vulnerability Identifier
Source
Related Link
Share with