Check: 2013-A-0135
windows 7 iavm:
2013-A-0135
(in version v1 r32)
Title
Microsoft GDI+ Remote Code Execution Vulnerability (Cat II impact)
Discussion
Microsoft has released a Security Bulletin addressing a remote code execution vulnerability affecting GDI. The Microsoft Windows graphics device interface (GDI) enables applications to use graphics and formatted text on both the video display and the printer. Windows-based applications do not access the graphics hardware directly. Instead, GDI interacts with device drivers on behalf of applications. To successfully exploit this vulnerability, an attacker would entice a user to view a malicious file that can embed specially crafted TrueType font files. If successfully exploited, this vulnerability would allow an attacker to take control of the affected system in the context of the current user.
Check Content
Fix Text
Additional Identifiers
Rule ID:
Vulnerability ID: V-39199
Group Title:
Expert Comments
CCIs
Number | Definition |
---|---|
No CCIs are assigned to this check |
Controls
Number | Title |
---|---|
No controls are assigned to this check |