Vulnerability Name: | CVE-2012-0165 (CCN-75125) | ||||||||
Assigned: | 2011-12-13 | ||||||||
Published: | 2012-05-08 | ||||||||
Updated: | 2018-10-12 | ||||||||
Summary: | GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2 and Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1 does not properly validate record types in EMF images, which allows remote attackers to execute arbitrary code via a crafted image, aka "GDI+ Record Type Vulnerability." | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 9.3 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C) 6.9 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
6.9 Medium (CCN Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-20 | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2012-0165 Source: CCN Type: SA49121 Microsoft Office Multiple Vulnerabilities Source: SECUNIA Type: UNKNOWN 49121 Source: CCN Type: Microsoft Security Bulletin MS12-034 Combined Security Update for Microsoft Office, Windows, .NET Framework, and Silverlight (2681578) Source: CCN Type: Microsoft Security Bulletin MS13-022 Vulnerability in Silverlight Could Allow Remote Code Execution (2814124) Source: CCN Type: Microsoft Security Bulletin MS13-054 Vulnerability in Windows Components Could Allow Remote Code Execution (2848295) Source: CCN Type: Microsoft Security Bulletin MS14-038 Vulnerability in Windows Journal Could Allow Remote Code Execution (2975689) Source: BID Type: UNKNOWN 53347 Source: CCN Type: BID-53347 Microsoft GDI+ CVE-2012-0165 EMF Image Processing Remote Code Execution Vulnerability Source: SECTRACK Type: UNKNOWN 1027038 Source: CERT Type: US Government Resource TA12-129A Source: MS Type: UNKNOWN MS12-034 Source: XF Type: UNKNOWN windows-gdi-emf-code-exec(75125) Source: XF Type: UNKNOWN windows-gdi-emf-code-exec(75125) Source: OVAL Type: UNKNOWN oval:org.mitre.oval:def:15621 | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
Oval Definitions | |||||||||
| |||||||||
BACK |