vendor:
Windows
by:
Anonymous
9,3
CVSS
HIGH
Arbitrary Memory Overwrite
119
CWE
Product Name: Windows
Affected Version From: Windows XP SP2
Affected Version To: Windows Server 2012
Patch Exists: Yes
Related CWE: CVE-2013-3128
CPE: o:microsoft:windows
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows XP SP3 and Windows 7 SP1
2013
DirectShow Arbitrary Memory Overwrite Vulnerability
Microsoft's DirectShow API is vulnerable to arbitrary memory overwrite when reading specially crafted GIF files. This vulnerability affects Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012.
Mitigation:
Microsoft has released a patch to address this vulnerability.