Wednesday, September 10, 2008

GDI+ interface update pack (MS08-052) problematic

Yesterday patched GDI+ interface sets specific challenges for system administrators. Interface is spread together with many Windows components and other Microsoft software, and also together with many 3rd party software installations. With 3rd party software spread interfaces are installed into either System32 directory of Windows or into product's own directory. Both cases bring problems.

If interface is installed into product's own directory must also these versions of interface be updated to protect system from vulnerabilities. If 3rd party software installs interface into System32 directory of Windows later into system installed software product may install vulnerable version of interface over Microsoft's version. If that happens the update must be re-installed.

System administrators should be careful when installing MS08-052 update. Installing Microsoft's update isn't enough to secure the system but all existing gdiplus.dll libraries in the system must be updated to the fixed version.

No comments: