CVE-2009-3678: Integer Overflow
Integer overflow in cdd.dll in the Canonical Display Driver (CDD) in Microsoft Windows Server 2008 R2 and Windows 7 on 64-bit platforms, when the Windows Aero theme is installed, allows context-dependent attackers to cause a denial of service (reboot) or possibly execute arbitrary code via a crafted image file that triggers incorrect data parsing after user-mode data is copied to kernel mode, as demonstrated using "Browse with Irfanview" and certain actions on a folder containing a large number of thumbnail images in Resample mode, possibly related to the ATI graphics driver or win32k.sys, aka "Canonical Display Driver Integer Overflow Vulnerability."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2009-3678?
CVE-2009-3678 is classified as a critical vulnerability due to its potential to cause a denial of service and execute arbitrary code.
How do I fix CVE-2009-3678?
To fix CVE-2009-3678, ensure your systems are updated with the latest security patches provided by Microsoft.
Which operating systems are affected by CVE-2009-3678?
CVE-2009-3678 affects Microsoft Windows Server 2008 R2 and Windows 7 on 64-bit platforms.
What kind of impact can CVE-2009-3678 have on my system?
CVE-2009-3678 can lead to system instability by causing a reboot or potentially allowing unauthorized code execution.
Who can exploit CVE-2009-3678?
CVE-2009-3678 can be exploited by context-dependent attackers with the ability to deliver crafted inputs to the system.