Microsoft Windows Knowledge Base Article 948590 update not installed (WinMs08kb948590Update)

Vuln ID: 41473
Risk Level: Low risk vulnerability  Low WinMs08kb948590Update
Platforms: Microsoft Windows 2000: SP4, Microsoft Windows 2003 Server: SP1, Microsoft Windows 2003 Server: SP1 Itanium, Microsoft Windows XP: x64-Professional, Microsoft Windows XP: SP2, Microsoft Windows 2003 Server: x64, Microsoft Windows XP: SP2 x64-Professional, Microsoft Windows Vista: x64, Microsoft Windows 2003 Server: SP2 Itanium, Microsoft Windows 2003 Server: SP2 x64, Microsoft Windows Vista, Microsoft Windows 2003 Server: SP2, Microsoft Windows 2008: Itanium, Microsoft Windows 2008, Microsoft Windows 2008: x64, Microsoft Windows Vista: SP1 x64, Microsoft Windows Vista: SP1
Description:

Microsoft Windows Knowledge Base Article 948850 update is not installed on the system, which could allow an attacker to exploit the following vulnerabilities:

Microsoft Windows graphic device interface (GDI) is vulnerable to an heap-based buffer overflow, caused by improper bounds checking of EMF and WMF image file headers. By persuading a victim to open a specially-crafted EMF or WMF file, a remote attacker could overflow a buffer and execute arbitrary code on the system.

Microsoft Windows graphic device interface (GDI) is vulnerable to an stack-based buffer overflow, caused by improper bounds checking of EMF image filename parameters. By persuading a victim to open a specially-crafted EMF file, a remote attacker could overflow a buffer and execute arbitrary code on the system.

Remedy:

Apply the appropriate patch for your system, as listed in Microsoft Security Bulletin MS08-021. See References.

False Positives:
False Negatives:
Required Permission: Windows login
Additional Information:

References:

Microsoft Security Bulletin MS08-021
Vulnerabilities in GDI Could Allow Remote Code Execution (948590)
http://www.microsoft.com/technet/security/bulletin/ms08-021.mspx

IBM Internet Security Systems X-Force Database
Microsoft Windows GDI EMF and WMF header buffer overflow
http://xforce.iss.net/xforce/xfdb/41471

IBM Internet Security Systems X-Force Database
Microsoft Windows GDI EMF filename parameter buffer overflow
http://xforce.iss.net/xforce/xfdb/41472

ISS X-Force
Microsoft Windows Knowledge Base Article 948590 update not installed
http://www.iss.net/security_center/static/41473.php

CVE CVE-2008-1087
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1087

CVE CVE-2008-1083
http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1083


X-Force Logo
Know Your Risks
Mitre.org CVE Logo
Common Vulnerabilties & Exposures