CVE-2012-0165: Input Validation
Published May 9, 2012
·Updated
GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2 and Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1 does not properly validate record types in EMF images, which allows remote attackers to execute arbitrary code via a crafted image, aka "GDI+ Record Type Vulnerability."
Affected Software
7 affected components
Microsoft Office=2003-sp3
Microsoft Office=2007-sp2
Microsoft Office=2007-sp3
Microsoft Office=2010
Microsoft Office=2010-sp1
Microsoft Windows Server 2008=sp2
Microsoft Windows Vista=sp2
Event History
May 9, 2012
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2012-0165?
CVE-2012-0165 is rated as critical due to its ability to allow remote code execution.
2
How do I fix CVE-2012-0165?
To fix CVE-2012-0165, apply the latest security patches provided by Microsoft for the affected software.
3
Which versions of software are affected by CVE-2012-0165?
CVE-2012-0165 impacts Microsoft Office 2003, 2007, 2010, and Windows Vista SP2 and Server 2008 SP2.
4
Can CVE-2012-0165 be exploited remotely?
Yes, CVE-2012-0165 can be exploited remotely through malicious EMF images.
5
What type of vulnerability is CVE-2012-0165 classified as?
CVE-2012-0165 is classified as a GDI+ Record Type Vulnerability.