Home / bulletins

MS07-046 - Critical: Vulnerability in GDI Could Allow Remote Code Execution (938829) - Version:1.0

Posted on 14 August 2007

There is an newer version: MS07-046 - Version: 1.1

Critical

Severity Rating: Critical - Revision Note: Bulletin ReleasedSummary: This critical security update resolves a privately reported vulnerability. A remote code execution vulnerability exists in the Graphics Rendering Engine in the way that it handles specially crafted images. An attacker could exploit the vulnerability by constructing a specially crafted image that could potentially allow remote code execution if a user opened a specially crafted attachment in e-mail. An attacker who successfully exploited this vulnerability could take complete control of an affected system.

Link

Other versions

 

TOP