(MS14-007) Vulnerability in Direct2D Could Allow Remote Code Execution (2912390)
Data de publicação: 18 fevereiro 2014
Schweregrad: : Crítico
Identificador(es) CVE: : CVE-2014-0263
Data do informe: 18 fevereiro 2014
Descrição
This update addresses a vulnerability that exists in the way Direct2D, a Windows component, handles objects in memory. An attacker can send a specially crafted 2-dimensional geometric figure to exploit this vulnerability. Once exploited, the attacker can execute any code on the vulnerable system.
Solução
Software infectado e versão:
- Windows 7 for 32-bit Systems Service Pack 1
- Windows 7 for x64-based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows 8 for 32-bit Systems
- Windows 8 for x64-based Systems
- Windows 8.1 for 32-bit Systems
- Windows 8.1 for x64-based Systems
- Windows Server 2012
- Windows Server 2012 R2
- Windows RT
- Windows RT 8.1