You are currently offline, waiting for your internet to reconnect

MS09-062: Description of the security update for GDI+ for all editions of Windows XP, Windows Vista, Windows Server 2003, and Windows Server 2008 and for Windows Server 2000 with Internet Explorer 6 Service Pack 1: October 13, 2009

Support for Windows XP has ended

Microsoft ended support for Windows XP on April 8, 2014. This change has affected your software updates and security options. Learn what this means for you and how to stay protected.

Support for Windows Server 2003 ended on July 14, 2015

Microsoft ended support for Windows Server 2003 on July 14, 2015. This change has affected your software updates and security options. Learn what this means for you and how to stay protected.

Support for Windows Vista Service Pack 1 (SP1) ends on July 12, 2011. To continue receiving security updates for Windows, make sure you're running Windows Vista with Service Pack 2 (SP2). For more information, refer to this Microsoft web page: Support is ending for some versions of Windows.
INTRODUCTION
Microsoft has released security bulletin MS09-062. To view the complete security bulletin, visit one of the following Microsoft Web sites:

How to obtain help and support for this security update

For home users, no-charge support is available by calling 1-866-PCSAFETY in the United States and Canada or by contacting your local Microsoft subsidiary. For more information about how to contact your local Microsoft subsidiary for support issues with security updates, visit the Microsoft International Support Web site: North American customers can also obtain instant access to unlimited no-charge e-mail support or to unlimited individual chat support by visiting the following Microsoft Web site: For enterprise customers, support for security updates is available through your usual support contacts.
MORE INFORMATION

Known issues with this security update

After you install this security update, you are not prompted to restart the computer. However, you must manually restart the computer for the update to take effect. Even though the update is installed successfully, the system will remain in a vulnerable state until it is restarted.
FILE INFORMATION
The English (United States) version of this software update installs files that have the attributes that are listed in the following tables. The dates and times for these files are listed in Coordinated Universal Time (UTC). The dates and times for these files on your local computer are displayed in your local time and with your current daylight saving time (DST) bias. Additionally, the dates and times may change when you perform certain operations on the files.

Windows 2000 file information

For all supported editions of Microsoft Windows 2000 Service Pack 4

File NameVersionDateTimeSize
iecustom.dll6.0.2800.158513-Oct-200611:2043,984
vgx.dll6.0.2800.163718-Aug-200907:382,360,832
iecustom.dll6.0.2800.158513-Oct-200611:2043,984

Windows XP and Windows Server 2003 file information

  • The files that apply to a specific service branch (QFE, GDR) are noted in the "Service branch" column.
  • GDR service branches contain only those fixes that are widely released to address widespread, critical issues. QFE service branches contain hotfixes in addition to widely released fixes.
  • In addition to the files that are listed in these tables, this software update also installs an associated security catalog file (KBnumber.cat) that is signed with a Microsoft digital signature.

For all supported x86-based versions of Windows XP

File NameVersionDateTimeSizeService branch
gdiplus.dll5.2.6001.2231913-Aug-200901:251,748,992SP3QFE\asms\10\msft\windows\gdiplus
update.ver-13-Aug-200914:1818update

For all supported x64-based versions of Windows Server 2003 and of Windows XP Professional x64 edition

File nameFile versionFile sizeDateTimePlatformSP requirementService branch
Gdiplus.dll5.2.6001.223192,192,38414-Aug-200903:23x64SP2SP2QFE\ASMS\10\MSFT\WINDOWS\GDIPLUS
Gdiplus.dll5.2.6001.223191,748,99214-Aug-200903:23x86SP2SP2QFE\ASMS\X86\10\MSFT\WINDOWS\GDIPLUS

For all supported x86-based versions of Windows Server 2003

File NameVersionDateTimeSizeService branch
gdiplus.dll5.2.6001.2231913-Aug-200901:371,748,992SP2QFE\asms\10\msft\windows\gdiplus
update.ver-13-Aug-200915:0218update

For all supported IA-64-based versions of Windows Server 2003

File NameVersionDateTimeSizeCPUService branch
gdiplus.dll5.2.6001.2231913-Aug-200914:444,910,080IA-64SP2QFE\asms\10\msft\windows\gdiplus
gdiplus.dll5.2.6001.2231913-Aug-200914:441,748,992X86SP2QFE\asms\x86\10\msft\windows\gdiplus
update.ver-13-Aug-200915:0318update

Windows Vista and Windows Server 2008 file information

  • The files that apply to a specific product, milestone (RTM, SPn), and service branch (LDR, GDR) can be identified by examining the file version numbers as shown in the following table:
    VersionProductMilestoneService branch
    6.0.6000.16xxxWindows VistaRTMGDR
    6.0.6000.20xxxWindows VistaRTMLDR
    6.0.6001.18xxxWindows Vista SP1 and Windows Server 2008 SP1SP1GDR
    6.0.6001.22xxxWindows Vista SP1 and Windows Server 2008 SP1SP1LDR
    6.0.6002.18xxxWindows Vista SP2 and Windows Server 2008 SP2SP2GDR
    6.0.6002.22xxxWindows Vista SP2 and Windows Server 2008 SP2SP2LDR
  • Service Pack 1 is integrated into the release version of Windows Server 2008. Therefore, RTM milestone files apply only to Windows Vista. RTM milestone files have a 6.0.0000.xxxxxx version number.
  • GDR service branches contain only those fixes that are widely released to address widespread, critical issues. LDR service branches contain hotfixes in addition to widely released fixes.

For all supported x86-based versions of Windows Vista and Windows Server 2008

File nameFile versionFile sizeDateTimePlatform
Gdiplus.dll5.2.6000.167821,744,89627-Nov-200804:35x86
Gdiplus.dll5.2.6000.209661,744,89627-Nov-200804:16x86
Gdiplus.dll5.2.6001.181751,748,99227-Nov-200804:35x86
Gdiplus.dll5.2.6001.223191,748,99227-Nov-200804:24x86
Gdiplus.dll6.0.6000.167821,823,23227-Nov-200804:35x86
Gdiplus.dll6.0.6000.209661,823,74427-Nov-200804:16x86
Gdiplus.dll6.0.6001.181751,823,74427-Nov-200804:35x86
Gdiplus.dll6.0.6001.223191,823,74427-Nov-200804:24x86

For all supported x64-based versions of Windows Vista and Windows Server 2008

File NameVersionDateTimeSizeCPUService branch
gdiplus.dll5.2.6000.1678226-Nov-200815:152,189,824X64Windows6.0-KB958869-x64\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16782_none_56f3d057b4f1e2e1
gdiplus.dll5.2.6000.2096626-Nov-200814:522,190,336X64Windows6.0-KB958869-x64\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.20966_none_4023cdbfce9b770e
gdiplus.dll5.2.6001.1817526-Nov-200815:192,191,872X64Windows6.0-KB958869-x64\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_56ce877db54422c4
gdiplus.dll5.2.6001.2231926-Nov-200816:022,192,384X64Windows6.0-KB958869-x64\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.22319_none_3ffa83bdcef15195
gdiplus.dll6.0.6000.1678226-Nov-200815:152,332,672X64Windows6.0-KB958869-x64\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.6000.16782_none_46453f3c4df7bc88
gdiplus.dll6.0.6000.2096626-Nov-200814:522,332,672X64Windows6.0-KB958869-x64\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.6000.20966_none_2f753ca467a150b5
gdiplus.dll6.0.6001.1817526-Nov-200815:192,332,672X64Windows6.0-KB958869-x64\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.6001.18175_none_461ff6624e49fc6b
gdiplus.dll6.0.6001.2231926-Nov-200816:022,333,184X64Windows6.0-KB958869-x64\amd64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.6001.22319_none_2f4bf2a267f72b3c
gdiplus.dll5.2.6000.1678226-Nov-200815:051,744,896X86Windows6.0-KB958869-x64\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.16782_none_9ea1072ec96e0be7
gdiplus.dll5.2.6000.2096626-Nov-200814:461,744,896X86Windows6.0-KB958869-x64\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6000.20966_none_87d10496e317a014
gdiplus.dll5.2.6001.1817526-Nov-200815:051,748,992X86Windows6.0-KB958869-x64\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54c9c04bca
gdiplus.dll5.2.6001.2231926-Nov-200814:541,748,992X86Windows6.0-KB958869-x64\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.22319_none_87a7ba94e36d7a9b
gdiplus.dll6.0.6000.1678226-Nov-200815:051,823,232X86Windows6.0-KB958869-x64\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.6000.16782_none_8df276136273e58e
gdiplus.dll6.0.6000.2096626-Nov-200814:461,823,744X86Windows6.0-KB958869-x64\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.6000.20966_none_7722737b7c1d79bb
gdiplus.dll6.0.6001.1817526-Nov-200815:051,823,744X86Windows6.0-KB958869-x64\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.6001.18175_none_8dcd2d3962c62571
gdiplus.dll6.0.6001.2231926-Nov-200814:541,823,744X86Windows6.0-KB958869-x64\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.6001.22319_none_76f929797c735442

For all supported IA-64-based versions of Windows Server 2008

File NameVersionDateTimeSizeCPUService branch
gdiplus.dll5.2.6001.1817526-Nov-200815:194,908,544IA-64Windows6.0-KB958869-ia64\ia64_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7b9c16c9c083ae
gdiplus.dll5.2.6001.2231926-Nov-200816:004,910,080IA-64Windows6.0-KB958869-ia64\ia64_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.22319_none_87a79856e36db27f
gdiplus.dll6.0.6001.1817526-Nov-200815:195,262,336IA-64Windows6.0-KB958869-ia64\ia64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.6001.18175_none_8dcd0afb62c65d55
gdiplus.dll6.0.6001.2231926-Nov-200816:005,263,360IA-64Windows6.0-KB958869-ia64\ia64_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.6001.22319_none_76f9073b7c738c26
gdiplus.dll5.2.6001.1817526-Nov-200815:051,748,992X86Windows6.0-KB958869-ia64\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54c9c04bca
gdiplus.dll5.2.6001.2231926-Nov-200814:541,748,992X86Windows6.0-KB958869-ia64\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.22319_none_87a7ba94e36d7a9b
gdiplus.dll6.0.6001.1817526-Nov-200815:051,823,744X86Windows6.0-KB958869-ia64\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.6001.18175_none_8dcd2d3962c62571
gdiplus.dll6.0.6001.2231926-Nov-200814:541,823,744X86Windows6.0-KB958869-ia64\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.6001.22319_none_76f929797c735442
update security_patch security_update security bug flaw vulnerability malicious attacker exploit registry unauthenticated buffer overrun overflow specially-formed scope specially-crafted denial of service DoS TSE
Properties

Article ID: 958869 - Last Review: 06/08/2011 19:02:00 - Revision: 2.2

Windows Server 2008 Service Pack 2, Windows Server 2008 Datacenter without Hyper-V, Windows Server 2008 Enterprise without Hyper-V, Windows Server 2008 for Itanium-Based Systems, Windows Server 2008 Standard without Hyper-V, Windows Server 2008 Datacenter, Windows Server 2008 Enterprise, Windows Server 2008 Standard, Windows Web Server 2008, Windows Vista Service Pack 2, Windows Vista Service Pack 1, Windows Vista Business, Windows Vista Enterprise, Windows Vista Home Basic, Windows Vista Home Premium, Windows Vista Starter, Windows Vista Ultimate, Windows Vista Enterprise 64-bit Edition, Windows Vista Home Basic 64-bit Edition, Windows Vista Home Premium 64-bit Edition, Windows Vista Ultimate 64-bit Edition, Windows Vista Business 64-bit Edition, Microsoft Windows Server 2003 Service Pack 2, Microsoft Windows XP Service Pack 2, Microsoft Windows XP Service Pack 3

  • atdownload kbbug kbexpertiseinter kbfix kbsecbulletin kbsecurity kbsecvulnerability kbsurveynew KB958869
Feedback