First published: Tue Nov 29 2005(Updated: )
Unspecified vulnerability in the Graphics Rendering Engine (GDI32.DLL) in Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1, related to "An unchecked buffer" and possibly buffer overflows, allows remote attackers to execute arbitrary code via a crafted Windows Metafile (WMF) format image, aka "Windows Metafile Vulnerability."
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Microsoft Windows 2003 Server | =64-bit | |
Microsoft Windows 2003 Server | =itanium | |
Microsoft Windows 2003 Server | =sp1 | |
Microsoft Windows XP | ||
Microsoft Windows XP | =sp1 | |
Microsoft Windows 2003 Server | =sp1 | |
Microsoft Windows 2003 Server | =r2 | |
Microsoft Windows 2000 | =sp4 | |
Microsoft Windows XP | =sp2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2005-2124 is classified as a critical vulnerability that can allow remote code execution.
To mitigate CVE-2005-2124, apply the latest security patches provided by Microsoft for affected operating systems.
CVE-2005-2124 affects Windows 2000 SP4, Windows XP SP1 and SP2, and Windows Server 2003 SP1.
CVE-2005-2124 allows remote attackers to execute arbitrary code through specially crafted Windows Metafile images.
If unable to patch for CVE-2005-2124, consider disabling the Graphics Rendering Engine, though this may affect system functionality.