Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2014-1818

Quick assessment

Affected
n/a n/a
Exploitation
High exploitation probability; assess promptly
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Microsoft GDI+(Graphics Device Interface,图形设备接口)是美国微软(Microsoft)公司的Windows XP和Windows Server 2003操作系统的子系统,也是.NET框架的重要组成部分,它负责在屏幕和打印机上绘制图形图像和显示信息。 Microsoft GDI+处理特制图像的验证的方式中存在一个远程执行代码漏洞。如果用户打开特制图像,则该漏洞可能允许远程执行代码。成功利用此漏洞的攻击者可以完全控制受影响的系统。以下软件受到影响:Microsoft

AI Predicted 9.8 Difficulty: Easy EPSS 20.22% · P97

Possible ATT&CK Techniques 1 AI

T1190 · Exploit Public-Facing Application
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2014-1818

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: CVE Program / CVE List V5
Vulnerability Description
GDI+ in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, Office 2007 SP3 and 2010 SP1 and SP2, Live Meeting 2007 Console, Lync 2010 and 2013, Lync 2010 Attendee, and Lync Basic 2013 allows remote attackers to execute arbitrary code via a crafted EMF+ record in an image file, aka "GDI+ Image Parsing Vulnerability."
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
Microsoft GDI+ 图像分析漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft GDI+(Graphics Device Interface,图形设备接口)是美国微软(Microsoft)公司的Windows XP和Windows Server 2003操作系统的子系统,也是.NET框架的重要组成部分,它负责在屏幕和打印机上绘制图形图像和显示信息。 Microsoft GDI+处理特制图像的验证的方式中存在一个远程执行代码漏洞。如果用户打开特制图像,则该漏洞可能允许远程执行代码。成功利用此漏洞的攻击者可以完全控制受影响的系统。以下软件受到影响:Microsoft
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
- n/a n/a -

II. Public POCs for CVE-2014-1818

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2014-1818

登录查看更多情报信息。

Vendor Advisories for CVE-2014-1818 (5)

Other References for CVE-2014-1818 (1)

Same Patch Batch · n/a · 2014-06-11 · 102 CVEs total

CVE-2014-1794 Microsoft Internet Explorer 内存损坏漏洞
CVE-2014-1817 Microsoft Unicode 脚本处理器漏洞
CVE-2014-1816 Microsoft MSXML 实体URI漏洞
CVE-2014-1811 Microsoft Windows TCP 拒绝服务漏洞
CVE-2014-1805 Microsoft Internet Explorer 内存损坏漏洞
CVE-2014-1804 Microsoft Internet Explorer 内存损坏漏洞
CVE-2014-1803 Microsoft Internet Explorer 内存损坏漏洞
CVE-2014-1802 Microsoft Internet Explorer 内存损坏漏洞
CVE-2014-1800 Microsoft Internet Explorer 内存损坏漏洞
CVE-2014-1799 Microsoft Internet Explorer 内存损坏漏洞
CVE-2014-1797 Microsoft Internet Explorer 内存损坏漏洞
CVE-2014-1796 Microsoft Internet Explorer 内存损坏漏洞
CVE-2014-1795 Microsoft Internet Explorer 内存损坏漏洞
CVE-2014-1782 Microsoft Internet Explorer 内存损坏漏洞
CVE-2014-1785 Microsoft Internet Explorer 内存损坏漏洞
CVE-2014-1784 Microsoft Internet Explorer 内存损坏漏洞
CVE-2014-1783 Microsoft Internet Explorer 内存损坏漏洞
CVE-2014-1786 Microsoft Internet Explorer 内存损坏漏洞
CVE-2014-1781 Microsoft Internet Explorer 内存损坏漏洞
CVE-2014-1780 Microsoft Internet Explorer 内存损坏漏洞

Showing top 20 of 102 CVEs. View all on vendor page → →

IV. Related Vulnerabilities

V. Comments for CVE-2014-1818

No comments yet


Leave a comment