A vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows. User interaction is required in that a user must open a malicious file or visit a malicious web page. The specific flaw exists within the parsing of malformed WMF files. A vulnerability exists in the GDI function CreateDIBPatternBrushPt used when processing WMF files. Due to a mis-calculation of user data a heap chunk can be under-allocated and later used resulting in a heap overflow. Successful exploitation can result in system compromise under the credentials of the currently logged in user.
You can download this advisory from the following link: https://packetstormsecurity.com/files/download/65345/ZDI-08-020.txt
Source: https://packetstormsecurity.com/files/65345/Zero-Day-Initiative-Advisory-08-020.html

