CERT-In Vulnerability Note
CIVN-2014-0280
Microsoft Graphics Component Information Disclosure Vulnerability
Original Issue Date:December 10, 2014
Severity Rating: HIGH
Systems Affected
- Windows Server 2003 SP2
- Windows Server 2003 x64 Edition SP2
- Windows Server 2003 with SP2 for Itanium-based Systems
- Windows Vista SP2
- Windows Vista x64 Edition SP2
- Windows Server 2008 for 32-bit Systems SP2 and x64-based Systems SP2
- Windows Server 2008 for Itanium-based Systems SP2
- Windows 7 for 32-bit Systems SP1 and x64-based Systems SP1
- Windows Server 2008 R2 for x64-based Systems SP1 and Itanium-based Systems SP1
- Windows 8 for 32-bit Systems and x64-based Systems
- Windows 8.1 for 32-bit Systems and x64-based Systems
- Windows Server 2012
- Windows Server 2012 R2
- Windows Server 2008 for 32-bit Systems SP2 and x64-based Systems SP2
- Windows Server 2008 R2 for x64-based Systems SP1
Overview
An information disclosure vulnerability has been reported in Microsoft Graphics Component which could allow a remote attacker to disclose sensitive information leading to further attacks on the system.
Description
An information disclosure vulnerability exists in Microsoft Graphics Component due to improper handling of the component while decoding JPEG images. A remote attacker could exploit this vulnerability by enticing a user to open a website containing a specially crafted image which could allow an attacker to predict the memory offsets of specific instructions in a given call stack. Successful exploitation of this vulnerability could allow the attacker to gain sensitive information about the system.
The attacker could use this vulnerability in conjunction with other vulnerabilities to conduct further attacks on the system.
Solution
Apply appropriate updates as mentioned in the Microsoft Security Bulletin
MS14-085
Vendor Information
Microsoft
https://technet.microsoft.com/library/security/ms14-085
References
Microsoft
https://technet.microsoft.com/library/security/ms14-085
Security Focus
http://www.securityfocus.com/bid/71502
Security Tracker
http://www.securitytracker.com/id/1031324
Cisco
http://tools.cisco.com/security/center/viewAlert.x?alertId=36599
CVE Name
CVE-2014-6355
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|