First published: Thu Dec 11 2014(Updated: )
The Graphics Component in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 does not properly process JPEG images, which makes it easier for remote attackers to bypass the ASLR protection mechanism via a crafted web site, aka "Graphics Component Information Disclosure Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 7 | =sp1 | |
Microsoft Windows 8.0 | ||
Microsoft Windows 8.1 | ||
Microsoft Windows RT | =gold | |
Microsoft Windows RT | ||
Microsoft Windows Server 2003 | =sp2 | |
Microsoft Windows Server 2008 Itanium | =sp2 | |
Microsoft Windows Server 2008 Itanium | =r2-sp1 | |
Microsoft Windows Server 2012 x64 | =gold | |
Microsoft Windows Server 2012 x64 | =r2 | |
Microsoft Windows Vista | =sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-6355 has been rated as critical by Microsoft due to its potential for remote code execution.
To fix CVE-2014-6355, apply the security updates provided by Microsoft through their official release channels.
CVE-2014-6355 affects multiple versions of Microsoft Windows including Windows Server 2003, Vista, 7, 8, 8.1, and Server 2008 and 2012.
The risks associated with CVE-2014-6355 include remote attackers exploiting the vulnerability to execute arbitrary code.
Yes, CVE-2014-6355 can potentially be exploited without user interaction, primarily through malicious JPEG images.