Vulnerability in Microsoft Graphics Component Could Allow Remote Code Execution (2896666)

Click any highlighted term for further explanation. For more information, contact technical support.

 

Details
Vulnerability name/brief description Vulnerability in Microsoft Graphics Component Could Allow Remote Code Execution (2896666)
CVE/CAN name
Vendor threat level Critical
SophosLabs threat level Critical
Solution FixIt tool available from https://support.microsoft.com/kb/2896666.
Vendor description Microsoft is investigating private reports of a vulnerability in the Microsoft Graphics component that affects Microsoft Windows, Microsoft Office, and Microsoft Lync. Microsoft is aware of targeted attacks that attempt to exploit this vulnerability in Microsoft Office products. The vulnerability is a remote code execution vulnerability that exists in the way affected components handle specially crafted TIFF images. An attacker could exploit this vulnerability by convincing a user to preview or open a specially crafted email message, open a specially crafted file, or browse specially crafted web content. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.
SophosLabs comments This is an out-of-band advisory from Microsoft warning about a vulnerability which exists in the Microsoft Graphics component. Specially crafted TIFF images can exploit this vulnerability and compromise the system. Microsoft have yet to release a patch to fix this vulnerability. In the meantime customers are advised to run the FixIt tool provided by Microsoft to block the vulnerable condition till a patch is released to fix this. At the time of writing, SophosLabs has not seen any samples in the wild which is exploiting this vulnerability.
SophosLabs testing result No SophosLabs testing result found
Currently known exploits
First sample seen 2013-11-05
Discovery date 05 Nov 2013
Affected software Windows Operating System:
Windows Vista Service Pack 2
Windows Vista x64 Edition Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for Itanium-based Systems Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation)

Microsoft Office Suites and Software:
Microsoft Office 2003 Service Pack 3
Microsoft Office 2007 Service Pack 3
Microsoft Office 2010 Service Pack 1 (32-bit editions)
Microsoft Office 2010 Service Pack 2 (32-bit editions)
Microsoft Office 2010 Service Pack 1 (64-bit editions)
Microsoft Office 2010 Service Pack 2 (64-bit editions)
Microsoft Office Compatibility Pack Service Pack 3

Microsoft Communication Platforms and Software:
Microsoft Lync 2010 (32-bit)
Microsoft Lync 2010 (64-bit)
Microsoft Lync 2010 Attendee
Microsoft Lync 2013 (32-bit)
Microsoft Lync Basic 2013 (32-bit)
Microsoft Lync 2013 (64-bit)
Microsoft Lync Basic 2013 (64-bit)
References
Credits
  • MAPP
  • Haifei Li of McAfee Labs IPS Team
Revisions
  • November 5, 2013 - Initial Revision Written

Explanation of terms

Vulnerability Name/Brief Description:

Vendor identifier plus a brief description of the type of attack.

CVE/CAN Name:

Currently assigned CVE name. If a CVE name doesn't exist the CAN name will be used until a CVE has been assigned.

Vendor Threat Level:

Threat level assigned by the vendor

SophosLabs Threat Level:

Threat level assigned by SophosLabs

  • LOW RISK - There is little chance of this vulnerability being actively exploited by malware.
  • MEDIUM RISK - There is a possibility of this vulnerability being actively exploited by malware.
  • HIGH RISK - There is a strong possibility of this vulnerability being actively exploited by malware.
  • CRITICAL RISK - This vulnerability will almost certainly be actively exploited by malware.

Solution:

Vendor-supplied Patch identifier and recommended solution, or workaround if applicable.

Vendor Description:

Summary of the cause and potential effect of the vulnerability provided by the vendor.

SophosLabs Comments:

SophosLabs' opinions and observations of the vulnerability in question.

SophosLabs Testing Result:

Details of completed lab testing, if applicable. Please note that the lab test environment may differ significantly from user environments.

Currently Known Exploits:

List of identities for known exploits, if applicable.

First Sample Seen:

Date of the first sample seen by SophosLabs.

Discovery Date:

Date of the earliest known publically disclosed advisory.

Affected Software:

Vulnerable platforms and software versions.