Microsoft Graphics Component Remote Code Execution Vulnerability
RISK: Extremely High Risk
TYPE: Clients - Productivity Products
A vulnerability was identified in Microsoft Office. A remote user can cause arbitrary code to be executed on the target user's system.
A remote user can create a specially crafted TIFF image file that, when loaded by the target user, will trigger a memory corruption flaw in a Microsoft graphics component and execute arbitrary code on the target system. The code will run with the privileges of the target user.
Note: Vendor patch is currently unavailable. This vulnerability is being actively exploited.
Impact
- Remote Code Execution
System / Technologies affected
- Windows Vista
- Windows Server 2008
- Microsoft Office 2003
- Microsoft Office 2007
- Microsoft Office 2010
- Microsoft Office Compatibility Pack Service Pack 3
- Microsoft Lync 2010
- Microsoft Lync 2013
Solutions
Note: Vendor patch is currently unavailable.
- Workarounds
- Disable the TIFF codec
https://support.microsoft.com/kb/2896666 - Deploy the Enhanced Mitigation Experience Toolkit
http://support.microsoft.com/kb/2458544
- Disable the TIFF codec
Vulnerability Identifier
Source
Related Link
Share with