CVE-2014-0263: Buffer Overflow
The Direct2D implementation in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a large 2D geometric figure that is encountered with Internet Explorer, aka "Microsoft Graphics Component Memory Corruption Vulnerability."
Affected Software
Remediation
Event History
Frequently Asked Questions
Which systems and application path are affected?
Systems running the listed Windows versions are exposed when Internet Explorer encounters a large 2D geometric figure. The vulnerability can allow remote arbitrary-code execution.
What does an attacker need to exploit this issue?
The vector indicates network reachability, no authentication requirement, and medium attack complexity. Exploitation may compromise confidentiality, integrity, and availability.
What should teams do to remediate the vulnerability?
A patch is available. Apply the available patch to affected systems.