MS15-097: Description of the security update for the graphics component in Windows Vista and Windows Server 2008: September 8, 2015

Summary
This security update resolves vulnerabilities in Windows, Microsoft Office, and Microsoft Lync. The most severe of these vulnerabilities could allow remote code execution if a user opens a specially crafted document or goes to an untrusted webpage that contains embedded OpenType fonts.

To learn more about the vulnerabilities, see Microsoft Security Bulletin MS15-097.
More information
Important
  • If you install a language pack after you install this update, you must reinstall this update. Therefore, we recommend that you install any language packs that you need before you install this update. For more information, see Add language packs to Windows.
How to obtain and install the update

Method 1: Windows Update

This update is available through Windows Update. When you turn on automatic updating, this update will be downloaded and installed automatically. For more information about how to turn on automatic updating, seeGet security updates automatically.

Method 2: Microsoft Download Center

You can obtain the stand-alone update package through the Microsoft Download Center. Follow the installation instructions on the download page to install the update.

Click the download link in Microsoft Security Bulletin MS15-097 that corresponds to the version of Windows that you are running.
More information

File information

The English (United States) version of this software update installs files that have the attributes that are listed in the following tables. The dates and times for these files are listed in Coordinated Universal Time (UTC). The dates and times for these files on your local computer are displayed in your local time and with your current daylight saving time (DST) bias. Additionally, the dates and times may change when you perform certain operations on the files.

Windows Vista and Windows Server 2008 file information

  • The files that apply to a specific product, milestone (SPn), and service branch (LDR, GDR) can be identified by examining the file version numbers as shown in the following table:
    VersionProductMilestoneService branch
    6.0.6002.19xxxWindows Vista SP2 and Windows Server 2008 SP2SP2GDR
    6.0.6002.23xxxWindows Vista SP2 and Windows Server 2008 SP2SP2LDR
  • GDR service branches contain only those fixes that are widely released to address widespread, critical issues. LDR service branches contain hotfixes in addition to widely released fixes.
Note The MANIFEST files (.manifest) and MUM files (.mum) that are installed are not listed.

For all supported x86-based versions of Windows Vista and Windows Server 2008

File nameFile versionFile sizeDateTimePlatform
Gdiplus.dll5.2.6002.194661,748,99206-Aug-201516:04x86
Gdiplus.dll5.2.6002.237751,748,99206-Aug-201515:32x86
Gdiplus.dll6.0.6002.194661,839,61606-Aug-201516:04x86
Gdiplus.dll6.0.6002.237751,839,61606-Aug-201515:32x86

For all supported x64-based versions of Windows Vista and Windows Server 2008

File nameFile versionFile sizeDateTimePlatform
Gdiplus.dll5.2.6002.194662,193,92006-Aug-201515:42x64
Gdiplus.dll5.2.6002.237752,194,43206-Aug-201515:35x64
Gdiplus.dll6.0.6002.194662,425,34406-Aug-201515:42x64
Gdiplus.dll6.0.6002.237752,425,85606-Aug-201515:35x64
Gdiplus.dll5.2.6002.194661,748,99206-Aug-201516:04x86
Gdiplus.dll5.2.6002.237751,748,99206-Aug-201515:32x86
Gdiplus.dll6.0.6002.194661,839,61606-Aug-201516:04x86
Gdiplus.dll6.0.6002.237751,839,61606-Aug-201515:32x86

For all supported IA-64-based versions of Windows Server 2008

File nameFile versionFile sizeDateTimePlatform
Gdiplus.dll5.2.6002.194664,913,15206-Aug-201515:21IA-64
Gdiplus.dll5.2.6002.237754,913,66406-Aug-201515:03IA-64
Gdiplus.dll6.0.6002.194665,268,48006-Aug-201515:21IA-64
Gdiplus.dll6.0.6002.237755,268,99206-Aug-201515:03IA-64
Gdiplus.dll5.2.6002.194661,748,99206-Aug-201516:04x86
Gdiplus.dll5.2.6002.237751,748,99206-Aug-201515:32x86
Gdiplus.dll6.0.6002.194661,839,61606-Aug-201516:04x86
Gdiplus.dll6.0.6002.237751,839,61606-Aug-201515:32x86

How to obtain help and support for this security update

Help for installing updates: Support for Microsoft Update

Security solutions for IT professionals: TechNet Security Troubleshooting and Support

Help for protecting your Windows-based computer from viruses and malware: Virus Solution and Security Center

Local support according to your country: International Support
malicious attacker exploit
Properties

Article ID: 3087135 - Last Review: 09/08/2015 17:39:00 - Revision: 1.0

Windows Server 2008 Service Pack 2, Windows Vista Service Pack 2

  • atdownload kbbug kbexpertiseinter kbfix kbsecbulletin kbsecurity kbsecvulnerability KB3087135
Feedback