main
Report a problem

MS04-028: Buffer Overrun in JPEG Processing (GDI+)

Toxicfume   on 15 September 2004 - 05:41 · 36 comments & 8617 views

Advertisement (Why?)
Thanks to xStainDx for the heads up.

Microsoft recommends that customers apply the update immediately.

This update resolves a newly-discovered, privately reported vulnerability. A buffer overrun vulnerability exists in the processing of JPEG image formats that could allow remote code execution on an affected system. The vulnerability is documented in this bulletin in its own section.

If a user is logged on with administrator privileges, an attacker who successfully exploited this vulnerability could take complete control of an affected system, including installing programs; viewing, changing, or deleting data; or creating new accounts with full privileges. Users whose accounts are configured to have fewer privileges on the system would be at less risk than users who operate with administrative privileges.

Maximum Severity Rating: Critical

Recommendation: Customers should apply the update immediately.

Security Update Replacement: None

View: Microsoft Technet

Post a comment · Send to friend Comments · There are 36 additional comments

Commenting has either been disabled on this article or you are not logged in. Click here to login or register, its free!

Note: Anonymous commenting is disabled in order to keep the quality of responses to a high standard.

Advertisement (Why?)