The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbitrary code via a Windows Metafile (WMF) format image with a crafted SETABORTPROC GDI Escape function call, related to the Windows Picture and Fax Viewer (SHIMGVW.DLL), a different vulnerability than CVE-2005-2123 and CVE-2005-2124, and as originally discovered in the wild on unionseek.com.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2005-12-28 19:03
Updated : 2024-02-04 16:52
NVD link : CVE-2005-4560
Mitre link : CVE-2005-4560
CVE.ORG link : CVE-2005-4560
JSON object : View
Products Affected
microsoft
- windows_xp
- windows_2003_server
CWE
CWE-20
Improper Input Validation