Tracker / CVE-2013-3906
CVE-2013-3906
Exploited High 7.8
GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010, 2010 Attendee, 2013, and Basic 2013 allows remote attackers to execute arbitrary code via a crafted TIFF image, as demonstrated by an image in a Word document, and exploited in the wild in October and November 2013.
Affected products and versions
| microsoft | excel_viewer |
|---|---|
| microsoft | lync |
| microsoft | office |
| microsoft | office_compatibility_pack |
| microsoft | powerpoint_viewer |
| microsoft | windows_server_2008 |
| microsoft | windows_vista |
| microsoft | word_viewer |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.