|CVSS SCORE||6.8, (AV:N/AC:M/Au:N/C:P/I:P/A:P)|
The specific flaw exists within the OleLoadPicture function. User-supplied data is used to calculate a buffer length for allocation and the function can then write beyond the buffer boundary. An attacker can leverage this functionality to execute arbitrary code in the context of the user.
Microsoft has issued an update to correct this vulnerability. More details can be found at: