Microsoft GDI+ Detection Tool is useless

From: Semjon (skatatschkow_at_hotmail.com)
Date: 10/02/04


Date: Sat, 2 Oct 2004 16:35:07 -0700

I don't get it - MS said that it provided a fix for the JPEG exploit. But all
I can see is this:

http://www.microsoft.com/downloads/details.aspx?familyid=71CD9E74-7142-4780-83E5-CE54401DA1D1&displaylang=en

It's the Microsoft GDI+ Detection Tool. So I downloaded it, installed it
and...it did absolutely nothing! Isn't it supposed to scan the harddisk for
all gdi libraries, test them for vulnerability and then display the results?
'Cause in my case it didn't - it just displayed a warning about possible
vulnerabilities being present and then redirected me to:

http://www.microsoft.com/security/bulletins/200409_jpeg_tool.mspx

So what? Great help! This page just redirects me to the office update site
plus offers some gdi detection tools for w2k and win2003.

Plus I have no idea how to re-launch the MS gdi detection tool to rescan the
harddisk. The only way to re-start it is to re-install it! So weird. Where
does it copy itself? I can't find it!

Anyway, it doesn't display WHICH programmes are affected. So it's totally
useless.

I found another scanner - http://isc.sans.org/gdiscan.php , this one indeed
scans the harddisks for vulnerable gdi libraries and displays them all in a
list. This really helps, cause now you can react and either update the
affected programmes or uninstall them if no new versions are available. Why
doesn't MS provide such a tool? Instead they offer their useless tool



Relevant Pages

  • Re: how to re-scan for GDI+ (jpeg) vulnerability?
    ... I downloaded the gdi detection tool as suggested. ... The only solution that's obvious to me is to to download the patches one by ... > Description of the Microsoft GDI+ Detection Tool ...
    (microsoft.public.windowsupdate)
  • KB822332 deployment not detected on machine
    ... I installed the office XP update for GDI+ vulnerability to some machines ... I don't want to use any detection tool (like MBSA). ...
    (microsoft.public.win2000.security)
  • How to run GD+ Detection Tool ?
    ... and apparently installed the GDI+ Detection Tool as... ... the Microsoft Download Center." ... Detection Tool was saved to run it... ... apps" must I run this after installing each piece of new software from now ...
    (microsoft.public.windowsxp.security_admin)
  • Re: GDI+
    ... the GDI+ Detection Tool is showing up again in windows update. ... Of course it still didn't automatically download and install at the time I ... > torgeir, Microsoft MVP Scripting and WMI, Porsgrunn Norway ...
    (microsoft.public.windowsupdate)
  • Microsoft Update on XP SP2 stops working after GDI Detection Tool is run
    ... My Windows XP SP2 installation was working until I ran the GDI ... Now if I try to access the Microsoft Update page IE ... I know that SP2 doesn't need the GDI Detection Tool ...
    (microsoft.public.windowsupdate)