Gravité: : Critique
  Identifiant(s) CVE: : CVE-2014-0263
  Date du conseil: 18 février 2014

  Description

This update addresses a vulnerability that exists in the way Direct2D, a Windows component, handles objects in memory. An attacker can send a specially crafted 2-dimensional geometric figure to exploit this vulnerability. Once exploited, the attacker can execute any code on the vulnerable system.

  Solutions

  Affected software and version:

  • Windows 7 for 32-bit Systems Service Pack 1
  • Windows 7 for x64-based Systems Service Pack 1
  • Windows Server 2008 R2 for x64-based Systems Service Pack 1
  • Windows 8 for 32-bit Systems
  • Windows 8 for x64-based Systems
  • Windows 8.1 for 32-bit Systems
  • Windows 8.1 for x64-based Systems
  • Windows Server 2012
  • Windows Server 2012 R2
  • Windows RT
  • Windows RT 8.1