MS14-036: Vulnerabilities in Microsoft Graphics Component Could Allow Remote Code Execution (2967487)

This script is Copyright (C) 2014-2016 Tenable Network Security, Inc.


Synopsis :

The remote Windows host is affected by multiple remote code execution
vulnerabilities.

Description :

The version of Microsoft's Graphics Component installed on the remote
host is affected by code execution vulnerabilities due to the way GDI+
handles image record types in specially crafted files. A remote,
unauthenticated attacker could exploit these issues by tricking a user
into viewing content that contains malicious files, which could result
in arbitrary code execution.

See also :

https://technet.microsoft.com/library/security/ms14-036

Solution :

Microsoft has released a set of patches for Windows Server 2003,
Vista, Server 2008, 7, 2008 R2, 8, 8.1, 2012, 2012 R2, Office 2007,
Office 2010, Live Meeting 2007 Console, Lync 2010, Lync 2010 Attendee,
Lync 2013, and Lync Basic 2013.

Risk factor :

High / CVSS Base Score : 9.3
(CVSS2#AV:N/AC:M/Au:N/C:C/I:C/A:C)
CVSS Temporal Score : 6.9
(CVSS2#E:U/RL:OF/RC:C)
Public Exploit Available : false

Family: Windows : Microsoft Bulletins

Nessus Plugin ID: 74428 ()

Bugtraq ID: 67897
67904

CVE ID: CVE-2014-1817
CVE-2014-1818

Ready to Scan Unlimited IPs & Run Compliance Checks?

Upgrade to Nessus Professional today!

Buy Now

Combine the Power of Nessus with the Ease of Cloud

Start your free Nessus Cloud trial now!

Begin Free Trial