|
Microsoft GDI+ EMF Image Processing Memory Corruption Vulnerability
Microsoft GDI+ is prone to a remote memory-corruption vulnerability that occurs when an application that uses the library tries to process a specially crafted EMF (Enhanced Metafile) image file. Successfully exploiting this issue would allow an attacker to execute arbitrary code in the context of the currently logged-in user. UPDATE (March 25, 2009): Further investigation reveals that technical details and an exploit regarding 'GpFont.SetData()', which were added to this BID on March 24, 2009, actually pertain to a new issue. Please see BID 34250 'Microsoft GDI+ EMF 'GpFont.SetData()' Buffer Overflow Vulnerability' for details. |
|
|
Privacy Statement |