<< Back
CVE Number Vulnerability Product Severity Date
MS07-046 Vulnerability in GDI Could Allow Remote Code Execution (938829) Microsoft Windows Critical 16-08-2007

Technical Information

Brief overview of the risk:
A remote code execution vulnerability exists in the Graphics Rendering Engine because of the way that it handles specially crafted images.
Detailed Information on the risk:
An attacker could exploit the vulnerability by constructing a specially crafted image that could potentially allow remote code execution if a user opened a specially crafted attachment in e-mail.
An attacker who successfully exploited this vulnerability could gain the same user rights as the local user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.Further information on this exploit is available at : MS07-046

Affected Software

Microsoft Windows 2000 Service Pack 4
Microsoft Windows Server 2003 Service Pack 1
Microsoft Windows Server 2003 with SP1 for Itanium-based Systems
Microsoft Windows Server 2003 x64 Edition
Microsoft Windows XP Professional x64 Edition
Microsoft Windows XP Service Pack 2