CERT-In Vulnerability Note
CIVN-2013-0195
Microsoft Graphics Component Remote Code Execution Vulnerability
Original Issue Date:November 07, 2013
Severity Rating: HIGH
Systems Affected
- Windows XP
- Windows Server 2003
- Windows Vista Service Pack 2
- Windows Vista x64 Edition Service Pack 2
- Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Server 2008 for x64-based Systems Service Pack 2
- Windows Server 2008 for Itanium-based Systems Service Pack 2
- Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
- Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)
Component Affected
- Microsoft Office 2003 Service Pack 3
- Microsoft Office 2007 Service Pack 3
- Microsoft Office 2010 Service Pack 1 (32-bit editions)
- Microsoft Office 2010 Service Pack 2 (64-bit editions)
- Microsoft Office Compatibility Pack Service Pack 3
- Microsoft Lync 2010 (32-bit)/(64 bit)/Attendee
- Microsoft Lync Basic 2013 (32-bit)/(64 Bit)
- Microsoft Lync 2013 (64-bit)/(32 bit)
Overview
A remote code execution vulnerability has been reported in the Microsoft Graphics Component (GDI+), which could allow a remote attacker to execute arbitrary code on a targeted system with the privileges of the logged in user.
Description
This vulnerability exists in the way that Graphics component processes specially crafted TIFF images.
The vulnerability could be exploited by a remote attacker by convincing a user to open specially crafted documents or browsing specially crafted web content to execute arbitrary code in the context of the current user.
Workaround
Solution
Apply appropriate updates as mentioned in the Microsoft Security Bulletin MS13-096
MS13-096
Vendor Information
Microsoft
http://technet.microsoft.com/en-us/security/advisory/2896666
References
Microsoft
http://technet.microsoft.com/en-us/security/advisory/2896666
http://blogs.technet.com/b/srd/archive/2013/11/05/cve-2013-3906-a-graphics-vulnerability-exploited-through-word-documents.aspx?Redirected=true
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=31655
Security Focus
http://www.securityfocus.com/bid/63530/info
CVE Name
CVE-2013-3906
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|