Microsoft Internet Explorer 6 SP1, Windows XP SP2 和 SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1和SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold 和SP3, Office Excel Viewer 2003 Gold以及SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1,和SP2, Word的微软Office文件格式兼容套装, Excel, 和PowerPoint 2007 File Formats SP1和SP2, Expression Web, Expression Web 2, Groove 2007 Gold 和 SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 和 SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold 和SP1,以及Forefront Client Security 1.0版本的GDI+没有使当地分配未明的缓冲区,这会允许远程攻击者可以借助特制的TIFF图像文件,且该文件能触发内存破坏,执行任意代码。该漏洞又称\"GDI+ TIFF Memory Corruption漏洞\"。
Microsoft Internet Explorer 6 SP1, Windows XP SP2 和 SP3, Windows Server 2003 SP2, Office XP SP3, Office 2003 SP3, 2007 Microsoft Office System SP1和SP2, Office Project 2002 SP1, Visio 2002 SP2, Office Word Viewer, Word Viewer 2003 Gold 和SP3, Office Excel Viewer 2003 Gold以及SP3, Office Excel Viewer, Office PowerPoint Viewer 2007 Gold, SP1,和SP2, Word的微软Office文件格式兼容套装, Excel, 和PowerPoint 2007 File Formats SP1和SP2, Expression Web, Expression Web 2, Groove 2007 Gold 和 SP1, Works 8.5, SQL Server 2000 Reporting Services SP2, SQL Server 2005 SP2 和 SP3, Report Viewer 2005 SP1, Report Viewer 2008 Gold 和SP1,以及Forefront Client Security 1.0版本的GDI+没有使当地分配未明的缓冲区,这会允许远程攻击者可以借助特制的TIFF图像文件,且该文件能触发内存破坏,执行任意代码。该漏洞又称\"GDI+ TIFF Memory Corruption漏洞\"。