J-Security Center

Title: Microsoft GDI+ WMF File Processing Remote Code Execution Vulnerability

Severity: HIGH

Description:

Microsoft GDI+ (graphics device interface) enables applications to use graphics and formatted text on the video display and on printers.

GDI+ is prone to a remote code-execution vulnerability because the vector graphics link library improperly processes Windows Metafile (WMF) image files. Specifically, the software fails to properly validate the size of a heap-based buffer before allocating memory for user-supplied data.

An attacker could exploit this issue to execute arbitrary code with the privileges of the currently logged-in user. Failed exploit attempts may crash applications that use the library.

Affected Products:

  • Microsoft Expression Web
  • Microsoft Expression Web 2
  • Microsoft Forefront Client Security 1.0
  • Microsoft Groove 2007
  • Microsoft Groove 2007 SP1
  • Microsoft Internet Explorer 6.0
  • Microsoft Internet Explorer 6.0 SP1
  • Microsoft Office 2003
  • Microsoft Office 2003 SP1
  • Microsoft Office 2003 SP2
  • Microsoft Office 2003 SP3
  • Microsoft Office 2007
  • Microsoft Office 2007 SP1
  • Microsoft Office 2007 SP2
  • Microsoft Office Compatibility Pack 2007
  • Microsoft Office Compatibility Pack 2007 SP1
  • Microsoft Office Compatibility Pack 2007 SP2
  • Microsoft Office Excel Viewer
  • Microsoft Office Excel Viewer 2003
  • Microsoft Office Excel Viewer 2003 SP3
  • Microsoft Office PowerPoint Viewer 2007
  • Microsoft Office PowerPoint Viewer 2007 SP1
  • Microsoft Office PowerPoint Viewer 2007 SP2
  • Microsoft Office Word 2003 Viewer
  • Microsoft Office Word 2003 Viewer SP3
  • Microsoft Office Word Viewer
  • Microsoft Office XP
  • Microsoft Office XP SP1
  • Microsoft Office XP SP2
  • Microsoft Office XP SP3
  • Microsoft Platform SDK Redistributable: GDI+
  • Microsoft Project 2002
  • Microsoft Project 2002
  • Microsoft Project 2002 SP1
  • Microsoft Report Viewer 2005 SP1
  • Microsoft Report Viewer 2008
  • Microsoft Report Viewer 2008 SP1
  • Microsoft SQL Server 2000 Reporting Services SP2
  • Microsoft SQL Server 2005
  • Microsoft SQL Server 2005 Express Edition
  • Microsoft SQL Server 2005 Express Edition SP1
  • Microsoft SQL Server 2005 Express Edition SP2
  • Microsoft SQL Server 2005 Itanium Edition
  • Microsoft SQL Server 2005 Itanium Edition SP1
  • Microsoft SQL Server 2005 Itanium Edition SP2
  • Microsoft SQL Server 2005 Itanium Edition SP3
  • Microsoft SQL Server 2005 SP1
  • Microsoft SQL Server 2005 SP2
  • Microsoft SQL Server 2005 SP3
  • Microsoft SQL Server 2005 x64 Edition SP1
  • Microsoft SQL Server 2005 x64 Edition SP2
  • Microsoft SQL Server 2005 x64 Edition SP3
  • Microsoft Visio 2002
  • Microsoft Visio 2002 Professional SP2
  • Microsoft Visio 2002 SP1
  • Microsoft Visio 2002 SP2
  • Microsoft Visual Basic .NET Standard 2003
  • Microsoft Visual C# .NET Standard 2003
  • Microsoft Visual C++ .NET Standard 2003
  • Microsoft Visual FoxPro 8.0
  • Microsoft Visual FoxPro 8.0 SP1
  • Microsoft Visual FoxPro 9.0 SP1
  • Microsoft Visual FoxPro 9.0 SP2
  • Microsoft Visual J# .NET Standard 2003
  • Microsoft Visual Studio .NET 2003
  • Microsoft Visual Studio .NET 2003
  • Microsoft Visual Studio .NET 2003 SP1
  • Microsoft Visual Studio 2005
  • Microsoft Visual Studio 2005 Professional Edition
  • Microsoft Visual Studio 2005 SP1
  • Microsoft Visual Studio 2005 Standard Edition
  • Microsoft Visual Studio 2005 Team Edition
  • Microsoft Visual Studio 2005 Team Edition for Architects
  • Microsoft Visual Studio 2005 Team Edition for Developers
  • Microsoft Visual Studio 2005 Team Edition for Testers
  • Microsoft Visual Studio 2008
  • Microsoft Visual Studio 2008 SP1
  • Microsoft Windows Server 2003 Datacenter Edition
  • Microsoft Windows Server 2003 Datacenter Edition Itanium
  • Microsoft Windows Server 2003 Enterprise Edition
  • Microsoft Windows Server 2003 Enterprise Edition Itanium
  • Microsoft Windows Server 2003 Standard Edition
  • Microsoft Windows Server 2003 Web Edition
  • Microsoft Windows XP
  • Microsoft Windows XP Embedded
  • Microsoft Windows XP Embedded SP1
  • Microsoft Windows XP Embedded SP2
  • Microsoft Windows XP Embedded SP3
  • Microsoft Windows XP Gold
  • Microsoft Windows XP Home
  • Microsoft Windows XP Home SP1
  • Microsoft Windows XP Home SP2
  • Microsoft Windows XP Home SP3
  • Microsoft Windows XP Media Center Edition
  • Microsoft Windows XP Media Center Edition SP1
  • Microsoft Windows XP Media Center Edition SP2
  • Microsoft Windows XP Media Center Edition SP3
  • Microsoft Windows XP Professional
  • Microsoft Windows XP Professional SP1
  • Microsoft Windows XP Professional SP2
  • Microsoft Windows XP Professional SP3
  • Microsoft Windows XP Tablet PC Edition
  • Microsoft Windows XP Tablet PC Edition SP1
  • Microsoft Windows XP Tablet PC Edition SP2
  • Microsoft Windows XP Tablet PC Edition SP3
  • Microsoft Word 2003 Viewer
  • Microsoft Word Viewer 2003 SP3
  • Microsoft Works 8.5

References:

Juniper Networks provides this content via a wide variety of sources and production methods. If notified of errors or omissions in the content of this page, Juniper Networks, at its discretion, will modify or remove the page or leave the content as is, depending on various factors including but not limited to the reputation and authority of the party providing the notification. Please use the contact information displayed elsewhere on this page to report any errors or omissions regarding the content on this page.