Skip to main content

Microsoft Graphics Component Remote Code Execution Vulnerability

Last Update Date: 6 Nov 2013 09:35 Release Date: 6 Nov 2013 4133 Views

RISK: Extremely High Risk

TYPE: Clients - Productivity Products

TYPE: Productivity Products

A vulnerability was identified in Microsoft Office. A remote user can cause arbitrary code to be executed on the target user's system.

 

A remote user can create a specially crafted TIFF image file that, when loaded by the target user, will trigger a memory corruption flaw in a Microsoft graphics component and execute arbitrary code on the target system. The code will run with the privileges of the target user.

 

Note: Vendor patch is currently unavailable. This vulnerability is being actively exploited.


Impact

  • Remote Code Execution

System / Technologies affected

  • Windows Vista
  • Windows Server 2008
  • Microsoft Office 2003
  • Microsoft Office 2007
  • Microsoft Office 2010
  • Microsoft Office Compatibility Pack Service Pack 3
  • Microsoft Lync 2010
  • Microsoft Lync 2013

Solutions

Note: Vendor patch is currently unavailable.


Vulnerability Identifier


Source


Related Link