MS14-036: Vulnerabilities in Microsoft Graphics Component Could Allow Remote Code Execution (2967487)

This script is Copyright (C) 2014 Tenable Network Security, Inc.


Synopsis :

The remote Windows host is affected by multiple remote code execution
vulnerabilities.

Description :

The version of Microsoft's Graphics Component installed on the remote
host is affected by code execution vulnerabilities due to the way GDI+
handles image record types in specially crafted files. A remote,
unauthenticated attacker could exploit these issues by tricking a user
into viewing content that contains malicious files, which could result
in arbitrary code execution.

See also :

http://technet.microsoft.com/en-us/security/bulletin/ms14-036

Solution :

Microsoft has released a set of patches for Windows Server 2003,
Vista, Server 2008, 7, 2008 R2, 8, 8.1, 2012, 2012 R2, Office 2007,
Office 2010, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee,
Lync 2013, and Lync Basic 2013.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 8.1
(CVSS2#E:ND/RL:OF/RC:C)
Public Exploit Available : false

Family: Windows : Microsoft Bulletins

Nessus Plugin ID: 74428 ()

Bugtraq ID: 67897
67904

CVE ID: CVE-2014-1817
CVE-2014-1818