Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-vjg7-x55q-x9jv

Опубликовано: 04 мая 2022
Источник: github
Github: Не прошло ревью

Описание

GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2 and Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1 does not properly validate record types in EMF images, which allows remote attackers to execute arbitrary code via a crafted image, aka "GDI+ Record Type Vulnerability."

GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2 and Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1 does not properly validate record types in EMF images, which allows remote attackers to execute arbitrary code via a crafted image, aka "GDI+ Record Type Vulnerability."

EPSS

Процентиль: 98%
0.62114
Средний

Дефекты

CWE-20

Связанные уязвимости

nvd
больше 13 лет назад

GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2 and Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1 does not properly validate record types in EMF images, which allows remote attackers to execute arbitrary code via a crafted image, aka "GDI+ Record Type Vulnerability."

EPSS

Процентиль: 98%
0.62114
Средний

Дефекты

CWE-20