
=====================================================================

                           CERT-Renater

               Note d'Information No. 2013/VULN543
_____________________________________________________________________

DATE                : 11/12/2013

HARDWARE PLATFORM(S): /

OPERATING SYSTEM(S): Windows version Vista, Server 2008,
                     running Microsoft Lync versions 2010, 2013,
                             Microsoft Office version 2003, 2007, 2010,
                             Microsoft Office Compatibility Pack,
                             Microsoft Office viewers.

======================================================================
KB2908005
https://technet.microsoft.com/en-us/security/bulletin/ms13-096
______________________________________________________________________

Microsoft Security Bulletin MS13-096 - Critical Vulnerability in
Microsoft Graphics Component Could Allow Remote Code Execution (2908005)

Published Date: December 10, 2013

Version: 1.0

General Information

Executive Summary

This security update resolves a publicly disclosed vulnerability in
Microsoft Windows, Microsoft Office, and Microsoft Lync. The
vulnerability could allow remote code execution if a user views content
that contains specially crafted TIFF files.

This security update is rated Critical for all supported editions of
Microsoft Office 2003, Microsoft Office 2007, Microsoft Office 2010, and
Microsoft Office Compatibility Pack. It is rated Important for all
supported editions of Windows Vista and Windows 2008, as well as all
supported editions of Microsoft Lync 2010 and Microsoft Lync 2013. For
more information, see the subsection, Affected and Non-Affected
Software, in this section.


Affected Software

Windows Vista Service Pack 2
Windows Vista x64 Edition Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2
Windows Server 2008 for x64-based Systems Service Pack 2
Windows Server 2008 for Itanium-based Systems Service Pack 2
Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core
  installation)
Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core
  installation)
Microsoft Office 2003 Service Pack 3
Microsoft Office 2007 Service Pack 3 [1]
Microsoft Office 2010 Service Pack 1 (32-bit editions)
Microsoft Office 2010 Service Pack 2 (32-bit editions)
Microsoft Office 2010 Service Pack 1
Microsoft Office 2010 Service Pack 2
Microsoft Office Compatibility Pack Service Pack 3[1]
Microsoft Lync 2010 (32-bit)
Microsoft Lync 2010 (64-bit)
Microsoft Lync 2010 Attendee [1] (user level install)
Microsoft Lync 2010 Attendee (admin level install)
Microsoft Lync 2013 (32-bit)
Microsoft Lync Basic 2013 (32-bit)
Microsoft Lync 2013 (64-bit)
Microsoft Lync Basic 2013 (64-bit)

[1]The update for Microsoft Office 2007 Service Pack 3 also applies to
Microsoft Office Compatibility Pack Service Pack 3.


Vulnerability Information

Microsoft Graphics Component Memory Corruption Vulnerability - CVE-2013-3906

A remote code execution vulnerability exists in the way that affected
Windows components and other affected software handle specially crafted
TIFF files.
The vulnerability could allow remote code execution if a user views TIFF
files in shared content. An attacker who successfully exploited this
vulnerability could take complete control of an affected system. An
attacker could then install programs; view, change, or delete data; or
create new accounts with full administrative rights.


=========================================================
Serveur de référence du CERT-Renater
https://services.renater.fr/ssi/
==========================================================
+ CERT-RENATER          | tel : 01-53-94-20-44           +
+ 23 - 25 Rue Daviel    | fax : 01-53-94-20-41           +
+ 75013 Paris           | email: cert@support.renater.fr +
==========================================================
