This application requires Javascript for optimal performance.

MS.GDIPlus.TIFF.Code.Execution

Release Date

Oct 14, 2009

Severity

critical

Impact

System compromise.

Description

This indicates a possible attempt to exploit a TIFF file format parsing vulnerability in gdiplus.dll. Successful attacks could lead to arbitrary code execution.

Affected Products

gdiplus.dll version 5.1.3102.2180
Other versions may also be affected

Recommended Actions

You may refer to Microsoft advisory for updates or patches:
http://www.microsoft.com/technet/security/Bulletin/ms09-062.mspx

Coverage

IPS
VCM

Common Vulnerabilities and Exposures (CVE)

CVE-2009-2502

Reference/s

http://www.securityfocus.com/bid/36646 (BugTraq)
http://technet.microsoft.com/en-us/security/bulletin/ms09-062.mspx (MS-ID)

Reference: VID-17816