Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Vulnerability protection

Microsoft Expression Design vulnerability could allow remote code execution


Report ID: MS201203006
Date Published: 14 March 2012

Criticality: Important
Compromise Type: remote-code-execution
Compromise From: remote


Affected Product/Component:

Microsoft Expression Design
Microsoft Expression Design 2
Microsoft Expression Design 3
Microsoft Expression Design 4




Summary

A vulnerability in Microsoft Expression Design could be used by an attacker to execute code and take control of a compromised system.



Detailed Description

Microsoft has released a security update for Expression Design to resolve a vulnerability that exists when loading DLL files. The vulnerability is caused by incorrection restriction of the path used for loading external files. Upon successful exploit, an attacker could be able to execute code and take complete control of a compromised system.

In the update, this vulnerability has been fixed by correcting the way Expression Design loads external libraries. To protect their system against potential exploit, users are recommended to install the update.

 



CVE Reference

CVE-2012-0016



Solution

Install the latest security patch for applicable system, available for download from (https://technet.microsoft.com/en-us/security/bulletin/ms12-022)



Security Advisories

For a list of known vulnerabilities affecting F-Secure products and the released fixes, please refer to the Security Advisories page.