>> Microsoft Windows GDI Code Execution Vulnerabilities (MS08-021)
Title : Microsoft Windows GDI Code Execution Vulnerabilities (MS08-021) VUPEN ID : VUPEN/ADV-2008-1145 CVE ID : CVE-2008-1083 - CVE-2008-1087
Rated as : Critical
Remotely Exploitable : Yes Locally Exploitable : Yes Release Date : 2008-04-08
Technical Description
Two vulnerabilities have been identified in Microsoft Windows, which could be exploited by remote attackers to cause a denial of service or take complete control of an affected system.
The first issue is caused by a heap overflow error in the graphics device interface (GDI) CreateDIBPatternBrushPt function when processing a malformed header in a specially crafted Windows Metafile (WMF) or Enhanced Metafile (EMF) image file, which could be exploited by attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.
The second vulnerability is caused by a stack overflow error in the graphics device interface (GDI) when processing a malformed file name parameter in a specially crafted Enhanced Metafile (EMF) image file, which could be exploited by attackers to execute arbitrary code by tricking a user into visiting a specially crafted web page.